CVE Vulnerabilities

CVE-2025-53860

Invocation of Process Using Visible Sensitive Information

Published: Oct 15, 2025 | Modified: Oct 21, 2025
CVSS 3.x
4.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Affected Software

Name Vendor Start Version End Version
F5os-a F5 1.5.1 (including) 1.5.3 (excluding)
F5os-a F5 1.8.0 (including) 1.8.0 (including)

References