CVE-2014-2928
published 2014-05-12CVE-2014-2928: The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1…
PriorityP263high7.1CVSS 2.0
AVNACHAuSCCICAC
EXPLOIT
EPSS
39.05%
98.4th percentile
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.
Affected
92 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_link_controller | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for POST requests to /iControl/iControlPortal.cgi over HTTPS (port 443) containing SOAP payloads with shell metacharacters (backticks) in the hostname element. ↗
- →Detect SOAP request bodies sent to iControlPortal.cgi where the hostname field contains backtick-wrapped commands (e.g., `cmd`.a.b pattern), indicating command injection attempt. ↗
- →Alert on creation or appending of files under /tmp/ with short random alpha names followed by execution via 'sh /tmp/<filename>', indicative of the exploit's staged payload delivery. ↗
- →Look for base64-chunked payloads (5-byte chunks) being decoded and written to /tmp/ via piped shell commands, a hallmark of this exploit's payload staging technique. ↗
- →The exploit uses HTTP Basic Authentication credentials embedded in the SOAP POST; monitor for repeated authenticated POST requests to iControlPortal.cgi with default credentials (admin/admin). ↗
- ·Exploitation requires valid administrator credentials; the vulnerability is authenticated RCE, not unauthenticated. Detection rules should account for authenticated sessions. ↗
- ·Affected versions span a wide range across multiple F5 product lines (LTM, APM, ASM, GTM, AAM, AFM, PEM, Analytics, Edge Gateway, WebAccelerator, WOM, Enterprise Manager, BIG-IQ); ensure version-scoped detection coverage. ↗
- ·The exploit targets the SOAP interface over SSL (port 443 by default); network inspection requires TLS decryption to detect malicious payloads in transit. ↗
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
team: fix check for port enabled in team_queue_override_port_prio_changed()
osv·2026-01-13·CVSS 7.8
CVE-2025-71091 team: fix check for port enabled in team_queue_override_port_prio_changed()
team: fix check for port enabled in team_queue_override_port_prio_changed()
In the Linux kernel, the following vulnerability has been resolved:
team: fix check for port enabled in team_queue_override_port_prio_changed()
There has been a syzkaller bug reported recently with the following
trace:
list_del corruption, ffff888058bea080->prev is LIST_POISON2 (dead000000000122)
------------[ cut here ]------------
kernel BUG at lib/list_debug.c:59!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 3 UID: 0 PID: 21246 Comm: syz.0.2928 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:__list_del_entry_valid_or_report+0x13e/0x200 lib/list_debug.c:59
Code: 48 c7 c7 e0 71 f0 8b e8 30 08 ef fc 90 0f
GHSA
GHSA-2ggw-q935-g2j9: The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10
ghsa_unreviewed·2022-05-17
CVE-2014-2928 [HIGH] GHSA-2ggw-q935-g2j9: The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.
No detection rules found.
Exploit-DB
F5 iControl - Remote Command Execution (Metasploit)
exploitdb·2014-10-09
CVE-2014-2928 F5 iControl - Remote Command Execution (Metasploit)
F5 iControl - Remote Command Execution (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 "F5 iControl Remote Root Command Execution",
'Description' => %q{
This module exploits an authenticated remote command execution
vulnerability in the F5 BIGIP iControl API (and likely other
F5 devices).
},
'License' => MSF_LICENSE,
'Author' =>
[
'bperry' # Discovery, Metasploit module
],
'References' =>
[
['CVE', '2014-2928'],
['URL', 'http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15220.html']
],
'Platform' => ['unix'],
'Arch' => ARCH_CMD,
'Targets' =>
[
['F5 iControl', {}]
],
'Privileged' => true,
'DisclosureDate' => "Sep 17 2013",
'DefaultTarge
Metasploit
F5 iControl Remote Root Command Execution
metasploit
F5 iControl Remote Root Command Execution
F5 iControl Remote Root Command Execution
This module exploits an authenticated remote command execution vulnerability in the F5 BIGIP iControl API (and likely other F5 devices).
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2014/May/32http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15220.htmlhttp://www.exploit-db.com/exploits/34927http://www.osvdb.org/106728http://seclists.org/fulldisclosure/2014/May/32http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15220.htmlhttp://www.exploit-db.com/exploits/34927http://www.osvdb.org/106728
2014-05-12
Published