Last Modified: Jan 10, 2026
Affected Product(s):
F5OS Velos
Known Affected Versions:
F5OS-A 1.8.3
Opened: Jan 07, 2026 Severity: 3-Major
When apply-to-root false is configured, password policy enforcement is inconsistent. Weak passwords (e.g., "a") are accepted during normal password changes but rejected during forced password changes (last-change 0), despite configuration explicitly disabling policy enforcement for root user.
Inconsistent password policy enforcement for root user
Configuration: system aaa password-policy config apply-to-root false Forced password change triggered via last-change 0
Option 1: Set apply-to-root true for consistent password policy enforcement (requires strong passwords) Option 2: Set strong password during forced change, then change to weak password afterward using normal method
None