CVE-2014-2928
published 2014-05-12CVE-2014-2928: The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1…
high7.1CVSS 3.1
AVNACHAuSCCICAC
EXPLOIT
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.
Affected
92 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_link_controller | — | — |
CVSS provenance
nvd7.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.8HIGH