BIG-IP Next SPK SSH vulnerability
CVE-2023-45226
7.4HIGH
What is CVE-2023-45226?
The Traffic Management Module (TMM) in F5 BIG-IP products has been found to contain hardcoded credentials within the f5-debug-sidecar and f5-debug-sshd containers. This security flaw allows an attacker who can intercept traffic to impersonate the SPK Secure Shell (SSH) server, posing significant risks when SSH debugging is enabled. Organizations using affected software versions should review their configurations to mitigate potential exploitation of this vulnerability, especially for versions that have not reached End of Technical Support.
Affected Version(s)
BIG-IP Next SPK 1.5.0 < 1.6.0