CVE-2022-41835 is a privilege escalation vulnerability affecting F5OS-A versions prior to 1.1.0 and F5OS-C versions prior to 1.5.0, caused by excessive file permissions within the operating system. Rated as High severity with a CVSS score of 8.8, this flaw allows an authenticated local attacker to execute unauthorized commands within a container, resulting in a scope change that can severely compromise the confidentiality, integrity, and availability of the F5OS controller. Despite the high risk score, intelligence sources indicate no active exploitation in the wild, and no proof-of-concept code or significant community discussion has been observed to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.1.0CPE matchmatch criteria | cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:* | ||
> 1.3.0, < 1.5.0CPE matchmatch criteria | cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.