F5OS
cpe:2.3:o:f5:f5os:*:*:*:*:*:*:*
- >= 1.5.1, <= 1.5.2
- >= 1.6.0, <= 1.6.2
A vulnerability exists in F5OS systems that allows SSH key-based authentication to remain active even after Appliance Mode is enabled. This issue arises when the root user initially configures the system for SSH key-based logins and later activates Appliance Mode. To exploit this vulnerability, an attacker must obtain the root user's SSH private key, corresponding to a key listed in the authorized_keys file.
Exploitation of this vulnerability could allow an attacker with access to a root user's SSH private key to log into the F5OS system while it is in Appliance Mode, bypassing the intended access controls.
To address this vulnerability, remove all configured public keys from the root user's authorized_keys file before enabling Appliance Mode. For F5OS-C users, an engineering hotfix is available. This hotfix can be downloaded from the MyF5 Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.