On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability they must obtain the root user's SSH private key. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Appliance Mode in F5OS systems is designed to restrict administrative access and block direct access to the system shell. However, if the root user previously configured key-based SSH authentication, this mechanism remains active after switching the system to Appliance Mode, contrary to the mode's intended behavior. An attacker who obtains the root user's private SSH key can log into the system while bypassing Appliance Mode restrictions. The vulnerability is classified as CWE-863 (improper authorization).
An attacker possessing the root user's private SSH key can gain full access to the F5OS system with root privileges, bypassing the restrictions imposed by Appliance Mode. This can lead to device takeover, breach of data confidentiality and integrity, and service unavailability.
Apply patches available from the vendor in accordance with the references (F5 article K000140574). Additionally, it is recommended to verify and remove authorized SSH keys of the root user on systems with Appliance Mode enabled, and to restrict access to the root user's private SSH keys.
F5OS systems running on F5OS-C and F5OS-A platforms where the root user had previously configured public key SSH authentication and subsequently Appliance Mode was enabled. Specific versions are indicated in the vendor references (K000140574). Versions that have reached End of Technical Support (EoTS) are not included in the assessment.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XF5 F5os A
OSF51.5.1 – 1.5.3 (excl.)F5 F5os C
OSF51.6.0 – 1.6.2
Related vulnerabilities
When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic...
A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access...
A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access ...
When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in S...
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator...