CVE-2024-23607
CVE-2024-23607 is a medium-severity vulnerability in F5 F5os-a with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- EPSS exploit prediction: 0% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-21101
- Weakness: CWE-22
- Affected product: F5 F5os-a
- Published:
- Last modified:
Description
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Frequently asked questions
- What is CVE-2024-23607?
- A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- How severe is CVE-2024-23607?
- CVE-2024-23607 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2024-23607 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-23607?
- CVE-2024-23607 primarily affects F5 F5os-a. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2024-23607?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-23607 have an EU (EUVD) identifier?
- Yes. CVE-2024-23607 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-21101.
- When was CVE-2024-23607 published?
- CVE-2024-23607 was published on 2024-02-14 and last updated on 2026-06-17.
References
Affected products (2)
- cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:*
- cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:*
More vulnerabilities in F5 F5os-a
- CVE-2025-57780 — High (CVSS 8.8): A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to…
- CVE-2025-61955 — High (CVSS 8.8): A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to…
- CVE-2025-46265 — High (CVSS 8.8): On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may…
- CVE-2025-36546 — High (CVSS 8.1): On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based…
- CVE-2002-20001 — High (CVSS 7.5): The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that…
- CVE-2022-41835 — High (CVSS 7.3): In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an…
All CVEs affecting F5 F5os-a →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.