CVE-2025-43878
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published:May 7, 2025
Last Modified:Feb 26, 2026
EPS:May 7, 2025
EPSS Score:0.00045
CVSS Score:6
Affected Products
Vendor
Product
Action
Vendor
F5
Product
F5os-a
F5
F5os-a
Vendor
F5
Product
F5os-c
F5
F5os-c
Vendor
F5
Product
R10600
F5
R10600
Vendor
F5
Product
R10800
F5
R10800
Vendor
F5
Product
R10900
F5
R10900
Vendor
F5
Product
R12600-ds
F5
R12600-ds
Vendor
F5
Product
R12800-ds
F5
R12800-ds
Vendor
F5
Product
R12900-ds
F5
R12900-ds
Vendor
F5
Product
R5600
F5
R5600
Vendor
F5
Product
R5800
F5
R5800
Vendor
F5
Product
R5900
F5
R5900
Vendor
F5
Product
Velos Cx1610
F5
Velos Cx1610
Vendor
F5
Product
Velos Cx410
F5
Velos Cx410
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
