CVE Vulnerabilities

CVE-2014-2927

Improper Authentication

Published: Oct 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ArxF56.0.0 (including)6.0.0 (including)
ArxF56.1.0 (including)6.1.0 (including)
ArxF56.1.1 (including)6.1.1 (including)
ArxF56.2.0 (including)6.2.0 (including)
ArxF56.3.0 (including)6.3.0 (including)
ArxF56.4.0 (including)6.4.0 (including)
Big-ip_access_policy_managerF510.1.0 (including)10.1.0 (including)
Big-ip_access_policy_managerF510.2.0 (including)10.2.0 (including)
Big-ip_access_policy_managerF510.2.1 (including)10.2.1 (including)
Big-ip_access_policy_managerF510.2.2 (including)10.2.2 (including)
Big-ip_access_policy_managerF510.2.3 (including)10.2.3 (including)
Big-ip_access_policy_managerF510.2.4 (including)10.2.4 (including)
Big-ip_access_policy_managerF511.0.0 (including)11.0.0 (including)
Big-ip_access_policy_managerF511.1.0 (including)11.1.0 (including)
Big-ip_access_policy_managerF511.2.0 (including)11.2.0 (including)
Big-ip_access_policy_managerF511.2.1 (including)11.2.1 (including)
Big-ip_access_policy_managerF511.3.0 (including)11.3.0 (including)
Big-ip_access_policy_managerF511.4.0 (including)11.4.0 (including)
Big-ip_access_policy_managerF511.4.1 (including)11.4.1 (including)
Big-ip_access_policy_managerF511.5.0 (including)11.5.0 (including)
Big-ip_access_policy_managerF511.5.1 (including)11.5.1 (including)
Big-ip_access_policy_managerF511.6.0 (including)11.6.0 (including)
Big-ip_advanced_firewall_managerF511.3.0 (including)11.3.0 (including)
Big-ip_advanced_firewall_managerF511.4.0 (including)11.4.0 (including)
Big-ip_advanced_firewall_managerF511.4.1 (including)11.4.1 (including)
Big-ip_advanced_firewall_managerF511.5.0 (including)11.5.0 (including)
Big-ip_advanced_firewall_managerF511.5.1 (including)11.5.1 (including)
Big-ip_advanced_firewall_managerF511.6.0 (including)11.6.0 (including)
Big-ip_analyticsF511.0.0 (including)11.0.0 (including)
Big-ip_analyticsF511.1.0 (including)11.1.0 (including)
Big-ip_analyticsF511.2.0 (including)11.2.0 (including)
Big-ip_analyticsF511.2.1 (including)11.2.1 (including)
Big-ip_analyticsF511.3.0 (including)11.3.0 (including)
Big-ip_analyticsF511.4.0 (including)11.4.0 (including)
Big-ip_analyticsF511.4.1 (including)11.4.1 (including)
Big-ip_analyticsF511.5.0 (including)11.5.0 (including)
Big-ip_analyticsF511.5.1 (including)11.5.1 (including)
Big-ip_analyticsF511.6.0 (including)11.6.0 (including)
Big-ip_application_acceleration_managerF511.4.0 (including)11.4.0 (including)
Big-ip_application_acceleration_managerF511.4.1 (including)11.4.1 (including)
Big-ip_application_acceleration_managerF511.5.0 (including)11.5.0 (including)
Big-ip_application_acceleration_managerF511.5.1 (including)11.5.1 (including)
Big-ip_application_acceleration_managerF511.6.0 (including)11.6.0 (including)
Big-ip_application_security_managerF510.0.0 (including)10.0.0 (including)
Big-ip_application_security_managerF510.0.1 (including)10.0.1 (including)
Big-ip_application_security_managerF510.1.0 (including)10.1.0 (including)
Big-ip_application_security_managerF510.2.0 (including)10.2.0 (including)
Big-ip_application_security_managerF510.2.1 (including)10.2.1 (including)
Big-ip_application_security_managerF510.2.2 (including)10.2.2 (including)
Big-ip_application_security_managerF510.2.3 (including)10.2.3 (including)
Big-ip_application_security_managerF510.2.4 (including)10.2.4 (including)
Big-ip_application_security_managerF511.0.0 (including)11.0.0 (including)
Big-ip_application_security_managerF511.1.0 (including)11.1.0 (including)
Big-ip_application_security_managerF511.2.0 (including)11.2.0 (including)
Big-ip_application_security_managerF511.2.1 (including)11.2.1 (including)
Big-ip_application_security_managerF511.3.0 (including)11.3.0 (including)
Big-ip_application_security_managerF511.4.0 (including)11.4.0 (including)
Big-ip_application_security_managerF511.4.1 (including)11.4.1 (including)
Big-ip_application_security_managerF511.5.0 (including)11.5.0 (including)
Big-ip_application_security_managerF511.5.1 (including)11.5.1 (including)
Big-ip_application_security_managerF511.6.0 (including)11.6.0 (including)
Big-ip_edge_gatewayF510.1.0 (including)10.1.0 (including)
Big-ip_edge_gatewayF510.2.0 (including)10.2.0 (including)
Big-ip_edge_gatewayF510.2.1 (including)10.2.1 (including)
Big-ip_edge_gatewayF510.2.2 (including)10.2.2 (including)
Big-ip_edge_gatewayF510.2.3 (including)10.2.3 (including)
Big-ip_edge_gatewayF510.2.4 (including)10.2.4 (including)
Big-ip_edge_gatewayF511.0.0 (including)11.0.0 (including)
Big-ip_edge_gatewayF511.1.0 (including)11.1.0 (including)
Big-ip_edge_gatewayF511.2.0 (including)11.2.0 (including)
Big-ip_edge_gatewayF511.2.1 (including)11.2.1 (including)
Big-ip_edge_gatewayF511.3.0 (including)11.3.0 (including)
Big-ip_global_traffic_managerF510.0.0 (including)10.0.0 (including)
Big-ip_global_traffic_managerF510.0.1 (including)10.0.1 (including)
Big-ip_global_traffic_managerF510.1.0 (including)10.1.0 (including)
Big-ip_global_traffic_managerF510.2.0 (including)10.2.0 (including)
Big-ip_global_traffic_managerF510.2.1 (including)10.2.1 (including)
Big-ip_global_traffic_managerF510.2.2 (including)10.2.2 (including)
Big-ip_global_traffic_managerF510.2.3 (including)10.2.3 (including)
Big-ip_global_traffic_managerF510.2.4 (including)10.2.4 (including)
Big-ip_global_traffic_managerF511.0.0 (including)11.0.0 (including)
Big-ip_global_traffic_managerF511.1.0 (including)11.1.0 (including)
Big-ip_global_traffic_managerF511.2.0 (including)11.2.0 (including)
Big-ip_global_traffic_managerF511.2.1 (including)11.2.1 (including)
Big-ip_global_traffic_managerF511.3.0 (including)11.3.0 (including)
Big-ip_global_traffic_managerF511.4.0 (including)11.4.0 (including)
Big-ip_global_traffic_managerF511.4.1 (including)11.4.1 (including)
Big-ip_global_traffic_managerF511.5.0 (including)11.5.0 (including)
Big-ip_global_traffic_managerF511.5.1 (including)11.5.1 (including)
Big-ip_global_traffic_managerF511.6.0 (including)11.6.0 (including)
Big-ip_link_controllerF510.0.0 (including)10.0.0 (including)
Big-ip_link_controllerF510.0.1 (including)10.0.1 (including)
Big-ip_link_controllerF510.1.0 (including)10.1.0 (including)
Big-ip_link_controllerF510.2.0 (including)10.2.0 (including)
Big-ip_link_controllerF510.2.1 (including)10.2.1 (including)
Big-ip_link_controllerF510.2.2 (including)10.2.2 (including)
Big-ip_link_controllerF510.2.3 (including)10.2.3 (including)
Big-ip_link_controllerF510.2.4 (including)10.2.4 (including)
Big-ip_link_controllerF511.0.0 (including)11.0.0 (including)
Big-ip_link_controllerF511.1.0 (including)11.1.0 (including)
Big-ip_link_controllerF511.2.0 (including)11.2.0 (including)
Big-ip_link_controllerF511.2.1 (including)11.2.1 (including)
Big-ip_link_controllerF511.3.0 (including)11.3.0 (including)
Big-ip_link_controllerF511.4.0 (including)11.4.0 (including)
Big-ip_link_controllerF511.4.1 (including)11.4.1 (including)
Big-ip_link_controllerF511.5.0 (including)11.5.0 (including)
Big-ip_link_controllerF511.5.1 (including)11.5.1 (including)
Big-ip_link_controllerF511.6.0 (including)11.6.0 (including)
Big-ip_local_traffic_managerF510.0.0 (including)10.0.0 (including)
Big-ip_local_traffic_managerF510.0.1 (including)10.0.1 (including)
Big-ip_local_traffic_managerF510.1.0 (including)10.1.0 (including)
Big-ip_local_traffic_managerF510.2.0 (including)10.2.0 (including)
Big-ip_local_traffic_managerF510.2.1 (including)10.2.1 (including)
Big-ip_local_traffic_managerF510.2.2 (including)10.2.2 (including)
Big-ip_local_traffic_managerF510.2.3 (including)10.2.3 (including)
Big-ip_local_traffic_managerF510.2.4 (including)10.2.4 (including)
Big-ip_local_traffic_managerF511.0.0 (including)11.0.0 (including)
Big-ip_local_traffic_managerF511.1.0 (including)11.1.0 (including)
Big-ip_local_traffic_managerF511.2.0 (including)11.2.0 (including)
Big-ip_local_traffic_managerF511.2.1 (including)11.2.1 (including)
Big-ip_local_traffic_managerF511.3.0 (including)11.3.0 (including)
Big-ip_local_traffic_managerF511.4.0 (including)11.4.0 (including)
Big-ip_local_traffic_managerF511.4.1 (including)11.4.1 (including)
Big-ip_local_traffic_managerF511.5.0 (including)11.5.0 (including)
Big-ip_local_traffic_managerF511.5.1 (including)11.5.1 (including)
Big-ip_local_traffic_managerF511.6.0 (including)11.6.0 (including)
Big-ip_policy_enforcement_managerF511.3.0 (including)11.3.0 (including)
Big-ip_policy_enforcement_managerF511.4.0 (including)11.4.0 (including)
Big-ip_policy_enforcement_managerF511.4.1 (including)11.4.1 (including)
Big-ip_policy_enforcement_managerF511.5.0 (including)11.5.0 (including)
Big-ip_policy_enforcement_managerF511.5.1 (including)11.5.1 (including)
Big-ip_policy_enforcement_managerF511.6.0 (including)11.6.0 (including)
Big-ip_protocol_security_moduleF510.0.0 (including)10.0.0 (including)
Big-ip_protocol_security_moduleF510.0.1 (including)10.0.1 (including)
Big-ip_protocol_security_moduleF510.1.0 (including)10.1.0 (including)
Big-ip_protocol_security_moduleF510.2.0 (including)10.2.0 (including)
Big-ip_protocol_security_moduleF510.2.1 (including)10.2.1 (including)
Big-ip_protocol_security_moduleF510.2.2 (including)10.2.2 (including)
Big-ip_protocol_security_moduleF510.2.3 (including)10.2.3 (including)
Big-ip_protocol_security_moduleF510.2.4 (including)10.2.4 (including)
Big-ip_protocol_security_moduleF511.0.0 (including)11.0.0 (including)
Big-ip_protocol_security_moduleF511.1.0 (including)11.1.0 (including)
Big-ip_protocol_security_moduleF511.2.0 (including)11.2.0 (including)
Big-ip_protocol_security_moduleF511.2.1 (including)11.2.1 (including)
Big-ip_protocol_security_moduleF511.3.0 (including)11.3.0 (including)
Big-ip_protocol_security_moduleF511.4.0 (including)11.4.0 (including)
Big-ip_protocol_security_moduleF511.4.1 (including)11.4.1 (including)
Big-ip_wan_optimization_managerF510.0.0 (including)10.0.0 (including)
Big-ip_wan_optimization_managerF510.0.1 (including)10.0.1 (including)
Big-ip_wan_optimization_managerF510.1.0 (including)10.1.0 (including)
Big-ip_wan_optimization_managerF510.2.0 (including)10.2.0 (including)
Big-ip_wan_optimization_managerF510.2.1 (including)10.2.1 (including)
Big-ip_wan_optimization_managerF510.2.2 (including)10.2.2 (including)
Big-ip_wan_optimization_managerF510.2.3 (including)10.2.3 (including)
Big-ip_wan_optimization_managerF510.2.4 (including)10.2.4 (including)
Big-ip_wan_optimization_managerF511.0.0 (including)11.0.0 (including)
Big-ip_wan_optimization_managerF511.1.0 (including)11.1.0 (including)
Big-ip_wan_optimization_managerF511.2.0 (including)11.2.0 (including)
Big-ip_wan_optimization_managerF511.2.1 (including)11.2.1 (including)
Big-ip_wan_optimization_managerF511.3.0 (including)11.3.0 (including)
Big-ip_webacceleratorF510.0.0 (including)10.0.0 (including)
Big-ip_webacceleratorF510.0.1 (including)10.0.1 (including)
Big-ip_webacceleratorF510.1.0 (including)10.1.0 (including)
Big-ip_webacceleratorF510.2.0 (including)10.2.0 (including)
Big-ip_webacceleratorF510.2.1 (including)10.2.1 (including)
Big-ip_webacceleratorF510.2.2 (including)10.2.2 (including)
Big-ip_webacceleratorF510.2.3 (including)10.2.3 (including)
Big-ip_webacceleratorF510.2.4 (including)10.2.4 (including)
Big-ip_webacceleratorF511.0.0 (including)11.0.0 (including)
Big-ip_webacceleratorF511.1.0 (including)11.1.0 (including)
Big-ip_webacceleratorF511.2.0 (including)11.2.0 (including)
Big-ip_webacceleratorF511.2.1 (including)11.2.1 (including)
Big-ip_webacceleratorF511.3.0 (including)11.3.0 (including)
Big-iq_cloudF54.0.0 (including)4.0.0 (including)
Big-iq_cloudF54.1.0 (including)4.1.0 (including)
Big-iq_cloudF54.2.0 (including)4.2.0 (including)
Big-iq_cloudF54.3.0 (including)4.3.0 (including)
Big-iq_deviceF54.2.0 (including)4.2.0 (including)
Big-iq_deviceF54.3.0 (including)4.3.0 (including)
Big-iq_securityF54.0.0 (including)4.0.0 (including)
Big-iq_securityF54.1.0 (including)4.1.0 (including)
Big-iq_securityF54.2.0 (including)4.2.0 (including)
Big-iq_securityF54.3.0 (including)4.3.0 (including)
Enterprise_managerF52.1.0 (including)2.1.0 (including)
Enterprise_managerF52.2.0 (including)2.2.0 (including)
Enterprise_managerF52.3.0 (including)2.3.0 (including)
Enterprise_managerF53.0.0 (including)3.0.0 (including)
Enterprise_managerF53.1.0 (including)3.1.0 (including)
Enterprise_managerF53.1.1 (including)3.1.1 (including)
FirepassF56.0.0 (including)6.0.0 (including)
FirepassF56.0.1 (including)6.0.1 (including)
FirepassF56.0.2 (including)6.0.2 (including)
FirepassF56.0.3 (including)6.0.3 (including)
FirepassF56.1.0 (including)6.1.0 (including)
FirepassF57.0.0 (including)7.0.0 (including)

Potential Mitigations

References