CVE-2025-60013
Severity CVSS v4.0:
MEDIUM
Type:
CWE-78
OS Command Injections
Publication date:
15/10/2025
Last modified:
04/02/2026
Description
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact
Base Score 4.0
4.60
Severity 4.0
MEDIUM
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:* | 1.5.1 (including) | 1.5.4 (excluding) |
| cpe:2.3:o:f5:f5os-a:1.8.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



