cbcvebase.
CVE-2014-2927
published 2014-10-15

CVE-2014-2927: The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1…

PriorityP270critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
7.92%
94.1th percentile
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.

Affected

195 ranges· showing 25
VendorProductVersion rangeFixed in
f5arx
f5arx
f5arx
f5arx
f5arx
f5arx
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager

Detection & IOCsextracted from sources · hover to see the quote

path/var/ssh/root
filenameauthorized_keys
othercmi
  • Alert on rsync write operations delivering files to /var/ssh/root (e.g., authorized_keys), which would indicate an attacker staging for root SSH access.
  • Detect unexpected SSH root logins to F5 BIG-IP or Enterprise Manager devices following inbound rsync traffic to the ConfigSync interface, as this is the post-exploitation step after key upload.
  • ·The vulnerability is only exploitable when the F5 BIG-IP or Enterprise Manager device is configured in failover/high-availability mode, which enables the unauthenticated rsync daemon on the ConfigSync interface.
  • ·Exploitation requires that the ConfigSync IP addresses are network-accessible to the attacker; restricting access to these interfaces at the network perimeter mitigates exposure.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.