ID

VAR-201405-0403


CVE

CVE-2014-2928


TITLE

plural F5 BIG-IP Series and BIG-IQ Family product iControl API Vulnerable to arbitrary command execution

Trust: 0.8

sources: JVNDB: JVNDB-2014-002461

DESCRIPTION

The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request. plural F5 BIG-IP Series and BIG-IQ Family product iControl API Contains a vulnerability that allows arbitrary command execution. Supplementary information : CWE Vulnerability type by CWE-77: Improper Neutralization of Special Elements used in a Command ( Command injection ) Has been identified. http://cwe.mitre.org/data/definitions/77.htmlBy a remote administrator SOAP An arbitrary command may be executed via a shell metacharacter in the hostname element of the request. F5 BIG-IP is a device product for application delivery services manufactured by F5 Network, which is mainly used for load balancing, business acceleration optimization and other purposes. A remote command injection vulnerability exists in multiple F5 BIG-IP products. Because the product fails to effectively filter the data provided through the iControl connection, this allows an attacker with a valid administrator account to exploit the vulnerability to access arbitrary commands on the affected system by accessing iControl. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks

Trust: 2.61

sources: NVD: CVE-2014-2928 // JVNDB: JVNDB-2014-002461 // CNVD: CNVD-2014-02934 // BID: 67278 // VULHUB: VHN-70867 // VULMON: CVE-2014-2928

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-02934

AFFECTED PRODUCTS

vendor:f5model:big-ip webacceleratorscope:eqversion:10.2.4

Trust: 1.9

vendor:f5model:big-ip access policy managerscope:eqversion:11.0.0

Trust: 1.6

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.2.1

Trust: 1.6

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.2.0

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.0.0

Trust: 1.6

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.1.0

Trust: 1.6

vendor:f5model:big-ip access policy managerscope:eqversion:10.2.1

Trust: 1.6

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.0.1

Trust: 1.6

vendor:f5model:big-ip access policy managerscope:eqversion:10.2.2

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.0

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:eqversion:10.2.1

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:10.2.2

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:10.2.1

Trust: 1.3

vendor:f5model:big-ip edge gatewayscope:eqversion:10.2.2

Trust: 1.3

vendor:f5model:big-ip edge gatewayscope:eqversion:10.2.1

Trust: 1.3

vendor:f5model:big-ip edge gatewayscope:eqversion:10.1.0

Trust: 1.3

vendor:f5model:big-ip local traffic managerscope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:9.4.7

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.2.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:10.0.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.7

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:10.2.2

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:10.2.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:9.4.6

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.2

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:10.2.1

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.3

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.6

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.5

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:10.0.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.2.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:10.2.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.2.2

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:10.0.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.0.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.2.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:10.0.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:9.4.8

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:10.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:10.2.3

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:10.2.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.8

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:10.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:10.0.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:9.4.4

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:9.4.5

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:10.2.2

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:10.2.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:10.2.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:10.2.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:10.1.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.0.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.0.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.0.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope:eqversion:10.1.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope:eqversion:11.0.0 to 11.3.0

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.0.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.0.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.0.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0 to 11.5.1

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.0.0 to 11.4.1

Trust: 0.8

vendor:f5model:big-ip wan optimization managerscope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.0.0 to 11.3.0

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope:eqversion:10.0.0 to 10.2.4

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope:eqversion:11.0.0 to 11.3.0

Trust: 0.8

vendor:f5model:big-iq cloudscope:eqversion:4.0.0 to 4.3.0

Trust: 0.8

vendor:f5model:big-iq devicescope:eqversion:4.2.0 to 4.3.0

Trust: 0.8

vendor:f5model:big-iq securityscope:eqversion:4.0.0 to 4.3.0

Trust: 0.8

vendor:f5model:enterprise managerscope:eqversion:2.1.0 to 2.3.0

Trust: 0.8

vendor:f5model:enterprise managerscope:eqversion:3.0.0 to 3.1.1

Trust: 0.8

vendor:f5model:big-ipscope: - version: -

Trust: 0.6

vendor:f5model:enterprise managerscope:eqversion:3.1

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:3.0

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:2.3

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:2.1

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.3

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.2

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.1

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.0

Trust: 0.3

vendor:f5model:big-iq devicescope:eqversion:4.3

Trust: 0.3

vendor:f5model:big-iq devicescope:eqversion:4.2

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.3

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.2

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.1

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.0

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:10.0

Trust: 0.3

vendor:f5model:big-ip wom hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip wom hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip wom hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip wom hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip wom hf3scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip wom hf7scope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip womscope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip wom hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:10.0

Trust: 0.3

vendor:f5model:big-ip webaccelerator hf5scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip webaccelerator hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:10.0

Trust: 0.3

vendor:f5model:big-ip psm hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip psm hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip psm hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip psm hf2scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip psm hf1scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip psm hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip psm hf3scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip psm hf2scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip psm hf7scope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip psm hf5scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip psm hf4scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip psm hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip pem hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.2.00

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip link controller hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip link controller hf3scope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:10.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip link controller hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip link controller hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip link controller hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip link controller hf5scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip link controller hf4scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip gtm hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:10.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip gtm hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip gtm hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip gtm hf2scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip gtm hf1scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip gtm hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip gtm hf3scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip gtm hf2scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip gtm hf7scope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip gtm hf5scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip gtm hf4scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip gtm hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:10.2

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip edge gateway 11.1.0-hf3scope: - version: -

Trust: 0.3

vendor:f5model:big-ip edge gateway 11.1.0-hf2scope: - version: -

Trust: 0.3

vendor:f5model:big-ip edge gateway 11.0.0-hf2scope: - version: -

Trust: 0.3

vendor:f5model:big-ip edge gateway 11.0.0-hf1scope: - version: -

Trust: 0.3

vendor:f5model:big-ip edge gateway 10.2.3-hf1scope: - version: -

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:eqversion:11.2.00

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.2.00

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.0.00

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:10.2.40

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:10.0.00

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip asm hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip asm hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asm hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asm hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip asm hf3scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip asm hf7scope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip asm hf5scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip asm hf4scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.4.0

Trust: 0.3

vendor:f5model:big-ip apm hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip apm hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apm hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apm hf2scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apm hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip apm hf3scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip apm hf2scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip apm hf7scope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip apm hf5scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip apm hf4scope:eqversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:10.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip analytics hf3scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analytics hf3scope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip analytics hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip analytics hf5scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analytics hf2scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analytics hf1scope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analytics hf5scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip analytics hf2scope:eqversion:11.2.0

Trust: 0.3

vendor:f5model:big-ip analytics hf7scope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip analytics 11.0.0-hf2scope: - version: -

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.0.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip afm hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.4.0

Trust: 0.3

sources: CNVD: CNVD-2014-02934 // BID: 67278 // JVNDB: JVNDB-2014-002461 // CNNVD: CNNVD-201405-217 // NVD: CVE-2014-2928

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2928
value: HIGH

Trust: 1.0

NVD: CVE-2014-2928
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-02934
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201405-217
value: HIGH

Trust: 0.6

VULHUB: VHN-70867
value: HIGH

Trust: 0.1

VULMON: CVE-2014-2928
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-2928
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:H/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2014-02934
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-70867
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:H/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-02934 // VULHUB: VHN-70867 // VULMON: CVE-2014-2928 // JVNDB: JVNDB-2014-002461 // CNNVD: CNNVD-201405-217 // NVD: CVE-2014-2928

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2014-002461 // NVD: CVE-2014-2928

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201405-217

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 67278

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002461

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-70867 // VULMON: CVE-2014-2928

PATCH

title:SOL15220: iControl vulnerability CVE-2014-2928url:http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15220.html

Trust: 0.8

title:Patch for multiple F5 BIG-IP product remote command injection vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/45490

Trust: 0.6

sources: CNVD: CNVD-2014-02934 // JVNDB: JVNDB-2014-002461

EXTERNAL IDS

db:NVDid:CVE-2014-2928

Trust: 3.5

db:OSVDBid:106728

Trust: 1.2

db:EXPLOIT-DBid:34927

Trust: 1.2

db:BIDid:67278

Trust: 1.0

db:JVNDBid:JVNDB-2014-002461

Trust: 0.8

db:CNNVDid:CNNVD-201405-217

Trust: 0.7

db:CNVDid:CNVD-2014-02934

Trust: 0.6

db:FULLDISCid:20140507 MOAR F5 FUN IN ICONTROL API

Trust: 0.6

db:PACKETSTORMid:126546

Trust: 0.1

db:PACKETSTORMid:128592

Trust: 0.1

db:VULHUBid:VHN-70867

Trust: 0.1

db:VULMONid:CVE-2014-2928

Trust: 0.1

sources: CNVD: CNVD-2014-02934 // VULHUB: VHN-70867 // VULMON: CVE-2014-2928 // BID: 67278 // JVNDB: JVNDB-2014-002461 // CNNVD: CNNVD-201405-217 // NVD: CVE-2014-2928

REFERENCES

url:http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15220.html

Trust: 2.7

url:http://seclists.org/fulldisclosure/2014/may/32

Trust: 2.6

url:http://www.exploit-db.com/exploits/34927

Trust: 1.2

url:http://www.osvdb.org/106728

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2928

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2928

Trust: 0.8

url:http://www.f5.com/products/big-ip/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://www.exploit-db.com/exploits/34927/

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.rapid7.com/db/modules/exploit/linux/http/f5_icontrol_exec

Trust: 0.1

sources: CNVD: CNVD-2014-02934 // VULHUB: VHN-70867 // VULMON: CVE-2014-2928 // BID: 67278 // JVNDB: JVNDB-2014-002461 // CNNVD: CNNVD-201405-217 // NVD: CVE-2014-2928

CREDITS

Brandon Perry

Trust: 0.3

sources: BID: 67278

SOURCES

db:CNVDid:CNVD-2014-02934
db:VULHUBid:VHN-70867
db:VULMONid:CVE-2014-2928
db:BIDid:67278
db:JVNDBid:JVNDB-2014-002461
db:CNNVDid:CNNVD-201405-217
db:NVDid:CVE-2014-2928

LAST UPDATE DATE

2024-11-23T23:05:46.974000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-02934date:2014-05-12T00:00:00
db:VULHUBid:VHN-70867date:2015-11-20T00:00:00
db:VULMONid:CVE-2014-2928date:2015-11-20T00:00:00
db:BIDid:67278date:2014-05-07T00:00:00
db:JVNDBid:JVNDB-2014-002461date:2014-05-14T00:00:00
db:CNNVDid:CNNVD-201405-217date:2014-05-14T00:00:00
db:NVDid:CVE-2014-2928date:2024-11-21T02:07:12.457

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-02934date:2014-05-12T00:00:00
db:VULHUBid:VHN-70867date:2014-05-12T00:00:00
db:VULMONid:CVE-2014-2928date:2014-05-12T00:00:00
db:BIDid:67278date:2014-05-07T00:00:00
db:JVNDBid:JVNDB-2014-002461date:2014-05-14T00:00:00
db:CNNVDid:CNNVD-201405-217date:2014-05-14T00:00:00
db:NVDid:CVE-2014-2928date:2014-05-12T14:55:06.587