{"id":"CVE-2025-60013","title":"When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) ma…","summary":"When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) ma…","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-78"],"vendor":"f5","product":"f5os-a","affected":["f5os-a >= 1.5.1, < 1.5.4","f5os-a = 1.8.0"],"patched":["f5os-a 1.5.4"],"published":"2025-10-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-60013","references":[{"url":"https://my.f5.com/manage/s/article/K000154661","label":"f5sirt@f5.com"}],"tags":["nvd","exploit-available"],"epss":0.0018,"epssPercentile":0.06977,"exploits":{"github":1,"githubRepos":["https://github.com/demining/Scalar-Venom-Attack"],"checkedAt":"2026-10-08T12:40:22.926Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T11:31:27.435Z","slug":"CVE-2025-60013","body":"## Overview\n\nWhen a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n## Affected\n\n- `f5os-a >= 1.5.1, < 1.5.4`\n- `f5os-a = 1.8.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `f5os-a 1.5.4`","depth":"twilight","depthScore":37,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}