CRITICAL🇵🇱 Wersja polska

CVE-2025-36546

CVSS 9.2v4.0pub. 2025-05-07upd. 2025-10-21

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability they must obtain the root user's SSH private key.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

🤖 AI Analysis
How it works

Appliance Mode in F5OS systems is designed to restrict administrative access and block direct access to the system shell. However, if the root user previously configured key-based SSH authentication, this mechanism remains active after switching the system to Appliance Mode, contrary to the mode's intended behavior. An attacker who obtains the root user's private SSH key can log into the system while bypassing Appliance Mode restrictions. The vulnerability is classified as CWE-863 (improper authorization).

Impact

An attacker possessing the root user's private SSH key can gain full access to the F5OS system with root privileges, bypassing the restrictions imposed by Appliance Mode. This can lead to device takeover, breach of data confidentiality and integrity, and service unavailability.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (F5 article K000140574). Additionally, it is recommended to verify and remove authorized SSH keys of the root user on systems with Appliance Mode enabled, and to restrict access to the root user's private SSH keys.

Who is affected

F5OS systems running on F5OS-C and F5OS-A platforms where the root user had previously configured public key SSH authentication and subsequently Appliance Mode was enabled. Specific versions are indicated in the vendor references (K000140574). Versions that have reached End of Technical Support (EoTS) are not included in the assessment.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • F5 F5os A

    OS
    F5
    1.5.1 – 1.5.3 (excl.)
  • F5 F5os C

    OS
    F5
    1.6.0 – 1.6.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-59778HIGH7.7same product

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic...

CVE-2025-61955HIGH8.5same product

A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access...

CVE-2025-57780HIGH8.5same product

A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access ...

CVE-2025-47150HIGH7.1same product

When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in S...

CVE-2025-43878HIGH8.3same product

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator...