CVE-2025-23239

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000138757 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:big-ip_access_policy_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_analytics:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_fraud_protection_service:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_global_traffic_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_link_controller:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:17.1.1:*:*:*:*:*:*:*

History

06 Aug 2025, 16:23

Type Values Removed Values Added
First Time F5 big-ip Fraud Protection Service
F5 big-ip Global Traffic Manager
F5 big-ip Application Acceleration Manager
F5 big-ip Advanced Firewall Manager
F5 big-ip Link Controller
F5 big-ip Analytics
F5 big-ip Access Policy Manager
F5
F5 big-ip Policy Enforcement Manager
F5 big-ip Local Traffic Manager
F5 big-ip Domain Name System
F5 big-ip Application Security Manager
References () https://my.f5.com/manage/s/article/K000138757 - () https://my.f5.com/manage/s/article/K000138757 - Vendor Advisory
Summary
  • (es) Cuando se ejecuta en modo de dispositivo, existe una vulnerabilidad de inyección de comandos remotos autenticados en un endpoint REST de iControl no revelado. Una explotación exitosa puede permitir que el atacante cruce un límite de seguridad. Nota: Las versiones de software que han alcanzado el fin del soporte técnico (EoTS) no se evalúan.
CPE cpe:2.3:a:f5:big-ip_advanced_firewall_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_analytics:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_global_traffic_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_access_policy_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_link_controller:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.1.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_fraud_protection_service:17.1.1:*:*:*:*:*:*:*

05 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 18:15

Updated : 2025-08-06 16:23


NVD link : CVE-2025-23239

Mitre link : CVE-2025-23239

CVE.ORG link : CVE-2025-23239


JSON object : View

Products Affected

f5

  • big-ip_domain_name_system
  • big-ip_global_traffic_manager
  • big-ip_advanced_firewall_manager
  • big-ip_access_policy_manager
  • big-ip_application_acceleration_manager
  • big-ip_link_controller
  • big-ip_local_traffic_manager
  • big-ip_policy_enforcement_manager
  • big-ip_fraud_protection_service
  • big-ip_analytics
  • big-ip_application_security_manager
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')