Lucene search

K
cveCertccCVE-2014-2927
HistoryOct 15, 2014 - 2:55 p.m.

CVE-2014-2927

2014-10-1514:55:06
CWE-287
certcc
web.nvd.nist.gov
39
f5 big-ip
enterprise manager
unauthenticated access
remote attack
arbitrary file access
cve-2014-2927

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.091

Percentile

94.7%

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.

Affected configurations

Nvd
Node
f5arxMatch6.0.0
OR
f5arxMatch6.1.0
OR
f5arxMatch6.1.1
OR
f5arxMatch6.2.0
OR
f5arxMatch6.3.0
OR
f5arxMatch6.4.0
OR
f5big-ip_access_policy_managerMatch10.1.0
OR
f5big-ip_access_policy_managerMatch10.2.0
OR
f5big-ip_access_policy_managerMatch10.2.1
OR
f5big-ip_access_policy_managerMatch10.2.2
OR
f5big-ip_access_policy_managerMatch10.2.3
OR
f5big-ip_access_policy_managerMatch10.2.4
OR
f5big-ip_access_policy_managerMatch11.0.0
OR
f5big-ip_access_policy_managerMatch11.1.0
OR
f5big-ip_access_policy_managerMatch11.2.0
OR
f5big-ip_access_policy_managerMatch11.2.1
OR
f5big-ip_access_policy_managerMatch11.3.0
OR
f5big-ip_access_policy_managerMatch11.4.0
OR
f5big-ip_access_policy_managerMatch11.4.1
OR
f5big-ip_access_policy_managerMatch11.5.0
OR
f5big-ip_access_policy_managerMatch11.5.1
OR
f5big-ip_access_policy_managerMatch11.6.0
OR
f5big-ip_advanced_firewall_managerMatch11.3.0
OR
f5big-ip_advanced_firewall_managerMatch11.4.0
OR
f5big-ip_advanced_firewall_managerMatch11.4.1
OR
f5big-ip_advanced_firewall_managerMatch11.5.0
OR
f5big-ip_advanced_firewall_managerMatch11.5.1
OR
f5big-ip_advanced_firewall_managerMatch11.6.0
OR
f5big-ip_analyticsMatch11.0.0
OR
f5big-ip_analyticsMatch11.1.0
OR
f5big-ip_analyticsMatch11.2.0
OR
f5big-ip_analyticsMatch11.2.1
OR
f5big-ip_analyticsMatch11.3.0
OR
f5big-ip_analyticsMatch11.4.0
OR
f5big-ip_analyticsMatch11.4.1
OR
f5big-ip_analyticsMatch11.5.0
OR
f5big-ip_analyticsMatch11.5.1
OR
f5big-ip_analyticsMatch11.6.0
OR
f5big-ip_application_acceleration_managerMatch11.4.0
OR
f5big-ip_application_acceleration_managerMatch11.4.1
OR
f5big-ip_application_acceleration_managerMatch11.5.0
OR
f5big-ip_application_acceleration_managerMatch11.5.1
OR
f5big-ip_application_acceleration_managerMatch11.6.0
OR
f5big-ip_application_security_managerMatch10.0.0
OR
f5big-ip_application_security_managerMatch10.0.1
OR
f5big-ip_application_security_managerMatch10.1.0
OR
f5big-ip_application_security_managerMatch10.2.0
OR
f5big-ip_application_security_managerMatch10.2.1
OR
f5big-ip_application_security_managerMatch10.2.2
OR
f5big-ip_application_security_managerMatch10.2.3
OR
f5big-ip_application_security_managerMatch10.2.4
OR
f5big-ip_application_security_managerMatch11.0.0
OR
f5big-ip_application_security_managerMatch11.1.0
OR
f5big-ip_application_security_managerMatch11.2.0
OR
f5big-ip_application_security_managerMatch11.2.1
OR
f5big-ip_application_security_managerMatch11.3.0
OR
f5big-ip_application_security_managerMatch11.4.0
OR
f5big-ip_application_security_managerMatch11.4.1
OR
f5big-ip_application_security_managerMatch11.5.0
OR
f5big-ip_application_security_managerMatch11.5.1
OR
f5big-ip_application_security_managerMatch11.6.0
OR
f5big-ip_edge_gatewayMatch10.1.0
OR
f5big-ip_edge_gatewayMatch10.2.0
OR
f5big-ip_edge_gatewayMatch10.2.1
OR
f5big-ip_edge_gatewayMatch10.2.2
OR
f5big-ip_edge_gatewayMatch10.2.3
OR
f5big-ip_edge_gatewayMatch10.2.4
OR
f5big-ip_edge_gatewayMatch11.0.0
OR
f5big-ip_edge_gatewayMatch11.1.0
OR
f5big-ip_edge_gatewayMatch11.2.0
OR
f5big-ip_edge_gatewayMatch11.2.1
OR
f5big-ip_edge_gatewayMatch11.3.0
OR
f5big-ip_global_traffic_managerMatch10.0.0
OR
f5big-ip_global_traffic_managerMatch10.0.1
OR
f5big-ip_global_traffic_managerMatch10.1.0
OR
f5big-ip_global_traffic_managerMatch10.2.0
OR
f5big-ip_global_traffic_managerMatch10.2.1
OR
f5big-ip_global_traffic_managerMatch10.2.2
OR
f5big-ip_global_traffic_managerMatch10.2.3
OR
f5big-ip_global_traffic_managerMatch10.2.4
OR
f5big-ip_global_traffic_managerMatch11.0.0
OR
f5big-ip_global_traffic_managerMatch11.1.0
OR
f5big-ip_global_traffic_managerMatch11.2.0
OR
f5big-ip_global_traffic_managerMatch11.2.1
OR
f5big-ip_global_traffic_managerMatch11.3.0
OR
f5big-ip_global_traffic_managerMatch11.4.0
OR
f5big-ip_global_traffic_managerMatch11.4.1
OR
f5big-ip_global_traffic_managerMatch11.5.0
OR
f5big-ip_global_traffic_managerMatch11.5.1
OR
f5big-ip_global_traffic_managerMatch11.6.0
OR
f5big-ip_link_controllerMatch10.0.0
OR
f5big-ip_link_controllerMatch10.0.1
OR
f5big-ip_link_controllerMatch10.1.0
OR
f5big-ip_link_controllerMatch10.2.0
OR
f5big-ip_link_controllerMatch10.2.1
OR
f5big-ip_link_controllerMatch10.2.2
OR
f5big-ip_link_controllerMatch10.2.3
OR
f5big-ip_link_controllerMatch10.2.4
OR
f5big-ip_link_controllerMatch11.0.0
OR
f5big-ip_link_controllerMatch11.1.0
OR
f5big-ip_link_controllerMatch11.2.0
OR
f5big-ip_link_controllerMatch11.2.1
OR
f5big-ip_link_controllerMatch11.3.0
OR
f5big-ip_link_controllerMatch11.4.0
OR
f5big-ip_link_controllerMatch11.4.1
OR
f5big-ip_link_controllerMatch11.5.0
OR
f5big-ip_link_controllerMatch11.5.1
OR
f5big-ip_link_controllerMatch11.6.0
OR
f5big-ip_local_traffic_managerMatch10.0.0
OR
f5big-ip_local_traffic_managerMatch10.0.1
OR
f5big-ip_local_traffic_managerMatch10.1.0
OR
f5big-ip_local_traffic_managerMatch10.2.0
OR
f5big-ip_local_traffic_managerMatch10.2.1
OR
f5big-ip_local_traffic_managerMatch10.2.2
OR
f5big-ip_local_traffic_managerMatch10.2.3
OR
f5big-ip_local_traffic_managerMatch10.2.4
OR
f5big-ip_local_traffic_managerMatch11.0.0
OR
f5big-ip_local_traffic_managerMatch11.1.0
OR
f5big-ip_local_traffic_managerMatch11.2.0
OR
f5big-ip_local_traffic_managerMatch11.2.1
OR
f5big-ip_local_traffic_managerMatch11.3.0
OR
f5big-ip_local_traffic_managerMatch11.4.0
OR
f5big-ip_local_traffic_managerMatch11.4.1
OR
f5big-ip_local_traffic_managerMatch11.5.0
OR
f5big-ip_local_traffic_managerMatch11.5.1
OR
f5big-ip_local_traffic_managerMatch11.6.0
OR
f5big-ip_policy_enforcement_managerMatch11.3.0
OR
f5big-ip_policy_enforcement_managerMatch11.4.0
OR
f5big-ip_policy_enforcement_managerMatch11.4.1
OR
f5big-ip_policy_enforcement_managerMatch11.5.0
OR
f5big-ip_policy_enforcement_managerMatch11.5.1
OR
f5big-ip_policy_enforcement_managerMatch11.6.0
OR
f5big-ip_protocol_security_moduleMatch10.0.0
OR
f5big-ip_protocol_security_moduleMatch10.0.1
OR
f5big-ip_protocol_security_moduleMatch10.1.0
OR
f5big-ip_protocol_security_moduleMatch10.2.0
OR
f5big-ip_protocol_security_moduleMatch10.2.1
OR
f5big-ip_protocol_security_moduleMatch10.2.2
OR
f5big-ip_protocol_security_moduleMatch10.2.3
OR
f5big-ip_protocol_security_moduleMatch10.2.4
OR
f5big-ip_protocol_security_moduleMatch11.0.0
OR
f5big-ip_protocol_security_moduleMatch11.1.0
OR
f5big-ip_protocol_security_moduleMatch11.2.0
OR
f5big-ip_protocol_security_moduleMatch11.2.1
OR
f5big-ip_protocol_security_moduleMatch11.3.0
OR
f5big-ip_protocol_security_moduleMatch11.4.0
OR
f5big-ip_protocol_security_moduleMatch11.4.1
OR
f5big-ip_wan_optimization_managerMatch10.0.0
OR
f5big-ip_wan_optimization_managerMatch10.0.1
OR
f5big-ip_wan_optimization_managerMatch10.1.0
OR
f5big-ip_wan_optimization_managerMatch10.2.0
OR
f5big-ip_wan_optimization_managerMatch10.2.1
OR
f5big-ip_wan_optimization_managerMatch10.2.2
OR
f5big-ip_wan_optimization_managerMatch10.2.3
OR
f5big-ip_wan_optimization_managerMatch10.2.4
OR
f5big-ip_wan_optimization_managerMatch11.0.0
OR
f5big-ip_wan_optimization_managerMatch11.1.0
OR
f5big-ip_wan_optimization_managerMatch11.2.0
OR
f5big-ip_wan_optimization_managerMatch11.2.1
OR
f5big-ip_wan_optimization_managerMatch11.3.0
OR
f5big-ip_webacceleratorMatch10.0.0
OR
f5big-ip_webacceleratorMatch10.0.1
OR
f5big-ip_webacceleratorMatch10.1.0
OR
f5big-ip_webacceleratorMatch10.2.0
OR
f5big-ip_webacceleratorMatch10.2.1
OR
f5big-ip_webacceleratorMatch10.2.2
OR
f5big-ip_webacceleratorMatch10.2.3
OR
f5big-ip_webacceleratorMatch10.2.4
OR
f5big-ip_webacceleratorMatch11.0.0
OR
f5big-ip_webacceleratorMatch11.1.0
OR
f5big-ip_webacceleratorMatch11.2.0
OR
f5big-ip_webacceleratorMatch11.2.1
OR
f5big-ip_webacceleratorMatch11.3.0
OR
f5big-iq_cloudMatch4.0.0
OR
f5big-iq_cloudMatch4.1.0
OR
f5big-iq_cloudMatch4.2.0
OR
f5big-iq_cloudMatch4.3.0
OR
f5big-iq_deviceMatch4.2.0
OR
f5big-iq_deviceMatch4.3.0
OR
f5big-iq_securityMatch4.0.0
OR
f5big-iq_securityMatch4.1.0
OR
f5big-iq_securityMatch4.2.0
OR
f5big-iq_securityMatch4.3.0
OR
f5enterprise_managerMatch2.1.0
OR
f5enterprise_managerMatch2.2.0
OR
f5enterprise_managerMatch2.3.0
OR
f5enterprise_managerMatch3.0.0
OR
f5enterprise_managerMatch3.1.0
OR
f5enterprise_managerMatch3.1.1
OR
f5firepassMatch6.0.0
OR
f5firepassMatch6.0.1
OR
f5firepassMatch6.0.2
OR
f5firepassMatch6.0.3
OR
f5firepassMatch6.1.0
OR
f5firepassMatch7.0.0
VendorProductVersionCPE
f5arx6.0.0cpe:2.3:a:f5:arx:6.0.0:*:*:*:*:*:*:*
f5arx6.1.0cpe:2.3:a:f5:arx:6.1.0:*:*:*:*:*:*:*
f5arx6.1.1cpe:2.3:a:f5:arx:6.1.1:*:*:*:*:*:*:*
f5arx6.2.0cpe:2.3:a:f5:arx:6.2.0:*:*:*:*:*:*:*
f5arx6.3.0cpe:2.3:a:f5:arx:6.3.0:*:*:*:*:*:*:*
f5arx6.4.0cpe:2.3:a:f5:arx:6.4.0:*:*:*:*:*:*:*
f5big-ip_access_policy_manager10.1.0cpe:2.3:a:f5:big-ip_access_policy_manager:10.1.0:*:*:*:*:*:*:*
f5big-ip_access_policy_manager10.2.0cpe:2.3:a:f5:big-ip_access_policy_manager:10.2.0:*:*:*:*:*:*:*
f5big-ip_access_policy_manager10.2.1cpe:2.3:a:f5:big-ip_access_policy_manager:10.2.1:*:*:*:*:*:*:*
f5big-ip_access_policy_manager10.2.2cpe:2.3:a:f5:big-ip_access_policy_manager:10.2.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 1951

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.091

Percentile

94.7%