ID

VAR-201512-0554


CVE

CVE-2015-3628


TITLE

plural F5 Product iControl API Vulnerability gained in

Trust: 0.8

sources: JVNDB: JVNDB-2015-006139

DESCRIPTION

The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0 through 11.4.1, Enterprise Manager 3.1.0 through 3.1.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote authenticated users with the "Resource Administrator" role to gain privileges via an iCall (1) script or (2) handler in a SOAP request to iControl/iControlPortal.cgi. plural F5 Product iControl API Contains a privileged vulnerability."Resource Administrator" By a remotely authenticated user with the role of iControl/iControlPortal.cgi To SOAP Request iCall of (1) Script or (2) There is a possibility that the privilege is obtained through the handler. Multiple F5 BIG-IP Products are prone to a privilege-escalation vulnerability. An attacker can exploit this issue to gain elevated privileges and perform unauthorized actions. F5 BIG-IP LTM, etc. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks. A security vulnerability exists in the iControl API of several F5 products due to the iControl/iControlPortal.cgi file not adequately filtering SOAP requests. 0 version, BIG-IQ ADC version 4.5.0

Trust: 1.98

sources: NVD: CVE-2015-3628 // JVNDB: JVNDB-2015-006139 // BID: 77666 // VULHUB: VHN-81589

AFFECTED PRODUCTS

vendor:f5model:big-ip edge gatewayscope:eqversion:11.3.0

Trust: 1.8

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.3.0

Trust: 1.8

vendor:f5model:big-ip webacceleratorscope:eqversion:11.3.0

Trust: 1.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.3

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.1

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.0

Trust: 1.6

vendor:f5model:big-ip enterprise managerscope:eqversion:3.1.0

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.0

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.2

Trust: 1.6

vendor:f5model:big-ip enterprise managerscope:eqversion:3.1.1

Trust: 1.6

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.1

Trust: 1.6

vendor:f5model:big-ip link controllerscope:eqversion:11.5.1

Trust: 1.3

vendor:f5model:big-ip analyticsscope:eqversion:11.5.1

Trust: 1.3

vendor:f5model:big-ip analyticsscope:eqversion:11.6.0

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5.2

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:11.4.1

Trust: 1.3

vendor:f5model:big-ip analyticsscope:eqversion:11.5.2

Trust: 1.3

vendor:f5model:big-ip analyticsscope:eqversion:11.4.1

Trust: 1.3

vendor:f5model:big-ip application security managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-iq cloudscope:eqversion:4.3.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-iq devicescope:eqversion:4.5.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-iq devicescope:eqversion:4.2.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-iq securityscope:eqversion:4.2.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-iq securityscope:eqversion:4.5.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-iq devicescope:eqversion:4.4.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-iq securityscope:eqversion:4.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-iq cloudscope:eqversion:4.2.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-iq securityscope:eqversion:4.4.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip enterprise managerscope:eqversion:3.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-iq cloudscope:eqversion:4.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-iq devicescope:eqversion:4.3.0

Trust: 1.0

vendor:f5model:big-iq cloudscope:eqversion:4.4.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-iq securityscope:eqversion:4.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-iq securityscope:eqversion:4.3.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-iq adcscope:eqversion:4.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-iq cloudscope:eqversion:4.5.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-iq cloudscope:eqversion:4.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0 to 11.6.0

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.3.0 to 11.4.1

Trust: 0.8

vendor:f5model:big-iq application delivery controllerscope:eqversion:4.5.0

Trust: 0.8

vendor:f5model:big-iq cloudscope:eqversion:4.0.0 to 4.5.0

Trust: 0.8

vendor:f5model:big-iq devicescope:eqversion:4.2.0 to 4.5.0

Trust: 0.8

vendor:f5model:big-iq securityscope:eqversion:4.0.0 to 4.5.0

Trust: 0.8

vendor:f5model:enterprise manager softwarescope:eqversion:3.1.0 to 3.1.1

Trust: 0.8

vendor:f5model:big-ip afmscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip afm hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:11.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip ltm hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.4

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.1.0

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip afm hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip pem hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip ltm hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip analytics hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:10.0

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:11.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip afmscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-iq devicescope:eqversion:4.3

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.3

Trust: 0.3

vendor:f5model:enterprise managerscope:neversion:2.3

Trust: 0.3

vendor:f5model:big-iq devicescope:eqversion:4.5

Trust: 0.3

vendor:f5model:big-ip apm hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-iq devicescope:eqversion:4.2

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.4.0

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip wom hf4scope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-ip pem hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip aam hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.4

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.0

Trust: 0.3

vendor:f5model:big-iq devicescope:eqversion:4.4

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.0

Trust: 0.3

vendor:f5model:big-ip pemscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.0.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.4

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:11.0.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.4.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip link controller hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.3

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.5

Trust: 0.3

vendor:f5model:enterprise managerscope:neversion:2.2

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:10.1

Trust: 0.3

vendor:f5model:enterprise managerscope:neversion:2.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.2

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.0.1

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.3.0

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.2

Trust: 0.3

vendor:f5model:enterprise managerscope:neversion:3.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.0

Trust: 0.3

vendor:f5model:big-ip gtm hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip aam hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.2.1

Trust: 0.3

vendor:f5model:big-ip asm hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-iq adcscope:eqversion:4.5

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.1.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.1

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.1.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip analytics hf2scope:neversion:11.5.3

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:11.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.1

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.3

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.5

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:10.2

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.5

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:10.2.3

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:3.1.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.4

Trust: 0.3

vendor:f5model:big-ip apm hf6scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:11.1

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:3.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:11.1.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:10.2.4

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:10.1.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:11.2

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-iq cloudscope:eqversion:4.4

Trust: 0.3

vendor:f5model:big-iq securityscope:eqversion:4.4

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip psmscope:neversion:10.2.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip aamscope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:11.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.3

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:10.0.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:10.2.4

Trust: 0.3

sources: BID: 77666 // JVNDB: JVNDB-2015-006139 // CNNVD: CNNVD-201512-083 // NVD: CVE-2015-3628

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3628
value: HIGH

Trust: 1.0

NVD: CVE-2015-3628
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201512-083
value: CRITICAL

Trust: 0.6

VULHUB: VHN-81589
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-3628
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-81589
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-81589 // JVNDB: JVNDB-2015-006139 // CNNVD: CNNVD-201512-083 // NVD: CVE-2015-3628

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-81589 // JVNDB: JVNDB-2015-006139 // NVD: CVE-2015-3628

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201512-083

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201512-083

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-006139

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-81589

PATCH

title:SOL16728: iCall privilege escalation vulnerability CVE-2015-3628url:https://support.f5.com/kb/en-us/solutions/public/16000/700/sol16728.html

Trust: 0.8

title:Multiple F5 Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=58944

Trust: 0.6

sources: JVNDB: JVNDB-2015-006139 // CNNVD: CNNVD-201512-083

EXTERNAL IDS

db:NVDid:CVE-2015-3628

Trust: 2.8

db:PACKETSTORMid:134434

Trust: 2.5

db:SECTRACKid:1034306

Trust: 1.7

db:SECTRACKid:1034307

Trust: 1.7

db:EXPLOIT-DBid:38764

Trust: 1.7

db:JVNDBid:JVNDB-2015-006139

Trust: 0.8

db:CNNVDid:CNNVD-201512-083

Trust: 0.7

db:BIDid:77666

Trust: 0.4

db:SEEBUGid:SSVID-90030

Trust: 0.1

db:VULHUBid:VHN-81589

Trust: 0.1

sources: VULHUB: VHN-81589 // BID: 77666 // JVNDB: JVNDB-2015-006139 // CNNVD: CNNVD-201512-083 // NVD: CVE-2015-3628

REFERENCES

url:http://packetstormsecurity.com/files/134434/f5-icontrol-icall-script-root-command-execution.html

Trust: 2.5

url:https://support.f5.com/kb/en-us/solutions/public/16000/700/sol16728.html

Trust: 2.0

url:https://www.exploit-db.com/exploits/38764/

Trust: 1.7

url:https://gdssecurity.squarespace.com/labs/2015/9/8/f5-icallscript-privilege-escalation-cve-2015-3628.html

Trust: 1.7

url:http://www.securitytracker.com/id/1034306

Trust: 1.7

url:http://www.securitytracker.com/id/1034307

Trust: 1.7

url:http://www.rapid7.com/db/modules/exploit/linux/http/f5_icall_cmd

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3628

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3628

Trust: 0.8

url:http/f5_icall_cmd

Trust: 0.6

url:http://www.rapid7.com/db/modules/exploit/linux/

Trust: 0.6

url:http://www.f5.com/products/big-ip/

Trust: 0.3

sources: VULHUB: VHN-81589 // BID: 77666 // JVNDB: JVNDB-2015-006139 // CNNVD: CNNVD-201512-083 // NVD: CVE-2015-3628

CREDITS

Tommaso Malgherini of Gotham Digital Science (GDS)

Trust: 0.3

sources: BID: 77666

SOURCES

db:VULHUBid:VHN-81589
db:BIDid:77666
db:JVNDBid:JVNDB-2015-006139
db:CNNVDid:CNNVD-201512-083
db:NVDid:CVE-2015-3628

LAST UPDATE DATE

2024-11-23T23:05:37.381000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-81589date:2019-06-06T00:00:00
db:BIDid:77666date:2015-11-09T00:00:00
db:JVNDBid:JVNDB-2015-006139date:2015-12-09T00:00:00
db:CNNVDid:CNNVD-201512-083date:2019-06-10T00:00:00
db:NVDid:CVE-2015-3628date:2024-11-21T02:29:31.077

SOURCES RELEASE DATE

db:VULHUBid:VHN-81589date:2015-12-07T00:00:00
db:BIDid:77666date:2015-11-09T00:00:00
db:JVNDBid:JVNDB-2015-006139date:2015-12-09T00:00:00
db:CNNVDid:CNNVD-201512-083date:2015-12-08T00:00:00
db:NVDid:CVE-2015-3628date:2015-12-07T20:59:04.587