vulnerability

F5 Networks: CVE-2023-45226: K000135874: BIG-IP Next SPK SSH vulnerability CVE-2023-45226

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:N)
Published
Oct 10, 2023
Added
Jan 9, 2024
Modified
Jan 28, 2025

Description


The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Solution

f5-big-ip-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.