CVE Vulnerabilities

CVE-2014-2927

Improper Authentication

Published: Oct 15, 2014 | Modified: Jan 26, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Arx F5 6.0.0 (including) 6.0.0 (including)
Arx F5 6.1.0 (including) 6.1.0 (including)
Arx F5 6.1.1 (including) 6.1.1 (including)
Arx F5 6.2.0 (including) 6.2.0 (including)
Arx F5 6.3.0 (including) 6.3.0 (including)
Arx F5 6.4.0 (including) 6.4.0 (including)
Big-ip_access_policy_manager F5 10.1.0 (including) 10.1.0 (including)
Big-ip_access_policy_manager F5 10.2.0 (including) 10.2.0 (including)
Big-ip_access_policy_manager F5 10.2.1 (including) 10.2.1 (including)
Big-ip_access_policy_manager F5 10.2.2 (including) 10.2.2 (including)
Big-ip_access_policy_manager F5 10.2.3 (including) 10.2.3 (including)
Big-ip_access_policy_manager F5 10.2.4 (including) 10.2.4 (including)
Big-ip_access_policy_manager F5 11.0.0 (including) 11.0.0 (including)
Big-ip_access_policy_manager F5 11.1.0 (including) 11.1.0 (including)
Big-ip_access_policy_manager F5 11.2.0 (including) 11.2.0 (including)
Big-ip_access_policy_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_access_policy_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_access_policy_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_access_policy_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_access_policy_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_access_policy_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_access_policy_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_advanced_firewall_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_advanced_firewall_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_advanced_firewall_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_advanced_firewall_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_advanced_firewall_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_advanced_firewall_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_analytics F5 11.0.0 (including) 11.0.0 (including)
Big-ip_analytics F5 11.1.0 (including) 11.1.0 (including)
Big-ip_analytics F5 11.2.0 (including) 11.2.0 (including)
Big-ip_analytics F5 11.2.1 (including) 11.2.1 (including)
Big-ip_analytics F5 11.3.0 (including) 11.3.0 (including)
Big-ip_analytics F5 11.4.0 (including) 11.4.0 (including)
Big-ip_analytics F5 11.4.1 (including) 11.4.1 (including)
Big-ip_analytics F5 11.5.0 (including) 11.5.0 (including)
Big-ip_analytics F5 11.5.1 (including) 11.5.1 (including)
Big-ip_analytics F5 11.6.0 (including) 11.6.0 (including)
Big-ip_application_acceleration_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_application_acceleration_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_application_acceleration_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_application_acceleration_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_application_acceleration_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_application_security_manager F5 10.0.0 (including) 10.0.0 (including)
Big-ip_application_security_manager F5 10.0.1 (including) 10.0.1 (including)
Big-ip_application_security_manager F5 10.1.0 (including) 10.1.0 (including)
Big-ip_application_security_manager F5 10.2.0 (including) 10.2.0 (including)
Big-ip_application_security_manager F5 10.2.1 (including) 10.2.1 (including)
Big-ip_application_security_manager F5 10.2.2 (including) 10.2.2 (including)
Big-ip_application_security_manager F5 10.2.3 (including) 10.2.3 (including)
Big-ip_application_security_manager F5 10.2.4 (including) 10.2.4 (including)
Big-ip_application_security_manager F5 11.0.0 (including) 11.0.0 (including)
Big-ip_application_security_manager F5 11.1.0 (including) 11.1.0 (including)
Big-ip_application_security_manager F5 11.2.0 (including) 11.2.0 (including)
Big-ip_application_security_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_application_security_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_application_security_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_application_security_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_application_security_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_application_security_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_application_security_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_edge_gateway F5 10.1.0 (including) 10.1.0 (including)
Big-ip_edge_gateway F5 10.2.0 (including) 10.2.0 (including)
Big-ip_edge_gateway F5 10.2.1 (including) 10.2.1 (including)
Big-ip_edge_gateway F5 10.2.2 (including) 10.2.2 (including)
Big-ip_edge_gateway F5 10.2.3 (including) 10.2.3 (including)
Big-ip_edge_gateway F5 10.2.4 (including) 10.2.4 (including)
Big-ip_edge_gateway F5 11.0.0 (including) 11.0.0 (including)
Big-ip_edge_gateway F5 11.1.0 (including) 11.1.0 (including)
Big-ip_edge_gateway F5 11.2.0 (including) 11.2.0 (including)
Big-ip_edge_gateway F5 11.2.1 (including) 11.2.1 (including)
Big-ip_edge_gateway F5 11.3.0 (including) 11.3.0 (including)
Big-ip_global_traffic_manager F5 10.0.0 (including) 10.0.0 (including)
Big-ip_global_traffic_manager F5 10.0.1 (including) 10.0.1 (including)
Big-ip_global_traffic_manager F5 10.1.0 (including) 10.1.0 (including)
Big-ip_global_traffic_manager F5 10.2.0 (including) 10.2.0 (including)
Big-ip_global_traffic_manager F5 10.2.1 (including) 10.2.1 (including)
Big-ip_global_traffic_manager F5 10.2.2 (including) 10.2.2 (including)
Big-ip_global_traffic_manager F5 10.2.3 (including) 10.2.3 (including)
Big-ip_global_traffic_manager F5 10.2.4 (including) 10.2.4 (including)
Big-ip_global_traffic_manager F5 11.0.0 (including) 11.0.0 (including)
Big-ip_global_traffic_manager F5 11.1.0 (including) 11.1.0 (including)
Big-ip_global_traffic_manager F5 11.2.0 (including) 11.2.0 (including)
Big-ip_global_traffic_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_global_traffic_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_global_traffic_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_global_traffic_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_global_traffic_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_global_traffic_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_global_traffic_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_link_controller F5 10.0.0 (including) 10.0.0 (including)
Big-ip_link_controller F5 10.0.1 (including) 10.0.1 (including)
Big-ip_link_controller F5 10.1.0 (including) 10.1.0 (including)
Big-ip_link_controller F5 10.2.0 (including) 10.2.0 (including)
Big-ip_link_controller F5 10.2.1 (including) 10.2.1 (including)
Big-ip_link_controller F5 10.2.2 (including) 10.2.2 (including)
Big-ip_link_controller F5 10.2.3 (including) 10.2.3 (including)
Big-ip_link_controller F5 10.2.4 (including) 10.2.4 (including)
Big-ip_link_controller F5 11.0.0 (including) 11.0.0 (including)
Big-ip_link_controller F5 11.1.0 (including) 11.1.0 (including)
Big-ip_link_controller F5 11.2.0 (including) 11.2.0 (including)
Big-ip_link_controller F5 11.2.1 (including) 11.2.1 (including)
Big-ip_link_controller F5 11.3.0 (including) 11.3.0 (including)
Big-ip_link_controller F5 11.4.0 (including) 11.4.0 (including)
Big-ip_link_controller F5 11.4.1 (including) 11.4.1 (including)
Big-ip_link_controller F5 11.5.0 (including) 11.5.0 (including)
Big-ip_link_controller F5 11.5.1 (including) 11.5.1 (including)
Big-ip_link_controller F5 11.6.0 (including) 11.6.0 (including)
Big-ip_local_traffic_manager F5 10.0.0 (including) 10.0.0 (including)
Big-ip_local_traffic_manager F5 10.0.1 (including) 10.0.1 (including)
Big-ip_local_traffic_manager F5 10.1.0 (including) 10.1.0 (including)
Big-ip_local_traffic_manager F5 10.2.0 (including) 10.2.0 (including)
Big-ip_local_traffic_manager F5 10.2.1 (including) 10.2.1 (including)
Big-ip_local_traffic_manager F5 10.2.2 (including) 10.2.2 (including)
Big-ip_local_traffic_manager F5 10.2.3 (including) 10.2.3 (including)
Big-ip_local_traffic_manager F5 10.2.4 (including) 10.2.4 (including)
Big-ip_local_traffic_manager F5 11.0.0 (including) 11.0.0 (including)
Big-ip_local_traffic_manager F5 11.1.0 (including) 11.1.0 (including)
Big-ip_local_traffic_manager F5 11.2.0 (including) 11.2.0 (including)
Big-ip_local_traffic_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_local_traffic_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_local_traffic_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_local_traffic_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_local_traffic_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_local_traffic_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_local_traffic_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_policy_enforcement_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_policy_enforcement_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_policy_enforcement_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_policy_enforcement_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_policy_enforcement_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_policy_enforcement_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_protocol_security_module F5 10.0.0 (including) 10.0.0 (including)
Big-ip_protocol_security_module F5 10.0.1 (including) 10.0.1 (including)
Big-ip_protocol_security_module F5 10.1.0 (including) 10.1.0 (including)
Big-ip_protocol_security_module F5 10.2.0 (including) 10.2.0 (including)
Big-ip_protocol_security_module F5 10.2.1 (including) 10.2.1 (including)
Big-ip_protocol_security_module F5 10.2.2 (including) 10.2.2 (including)
Big-ip_protocol_security_module F5 10.2.3 (including) 10.2.3 (including)
Big-ip_protocol_security_module F5 10.2.4 (including) 10.2.4 (including)
Big-ip_protocol_security_module F5 11.0.0 (including) 11.0.0 (including)
Big-ip_protocol_security_module F5 11.1.0 (including) 11.1.0 (including)
Big-ip_protocol_security_module F5 11.2.0 (including) 11.2.0 (including)
Big-ip_protocol_security_module F5 11.2.1 (including) 11.2.1 (including)
Big-ip_protocol_security_module F5 11.3.0 (including) 11.3.0 (including)
Big-ip_protocol_security_module F5 11.4.0 (including) 11.4.0 (including)
Big-ip_protocol_security_module F5 11.4.1 (including) 11.4.1 (including)
Big-ip_wan_optimization_manager F5 10.0.0 (including) 10.0.0 (including)
Big-ip_wan_optimization_manager F5 10.0.1 (including) 10.0.1 (including)
Big-ip_wan_optimization_manager F5 10.1.0 (including) 10.1.0 (including)
Big-ip_wan_optimization_manager F5 10.2.0 (including) 10.2.0 (including)
Big-ip_wan_optimization_manager F5 10.2.1 (including) 10.2.1 (including)
Big-ip_wan_optimization_manager F5 10.2.2 (including) 10.2.2 (including)
Big-ip_wan_optimization_manager F5 10.2.3 (including) 10.2.3 (including)
Big-ip_wan_optimization_manager F5 10.2.4 (including) 10.2.4 (including)
Big-ip_wan_optimization_manager F5 11.0.0 (including) 11.0.0 (including)
Big-ip_wan_optimization_manager F5 11.1.0 (including) 11.1.0 (including)
Big-ip_wan_optimization_manager F5 11.2.0 (including) 11.2.0 (including)
Big-ip_wan_optimization_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_wan_optimization_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_webaccelerator F5 10.0.0 (including) 10.0.0 (including)
Big-ip_webaccelerator F5 10.0.1 (including) 10.0.1 (including)
Big-ip_webaccelerator F5 10.1.0 (including) 10.1.0 (including)
Big-ip_webaccelerator F5 10.2.0 (including) 10.2.0 (including)
Big-ip_webaccelerator F5 10.2.1 (including) 10.2.1 (including)
Big-ip_webaccelerator F5 10.2.2 (including) 10.2.2 (including)
Big-ip_webaccelerator F5 10.2.3 (including) 10.2.3 (including)
Big-ip_webaccelerator F5 10.2.4 (including) 10.2.4 (including)
Big-ip_webaccelerator F5 11.0.0 (including) 11.0.0 (including)
Big-ip_webaccelerator F5 11.1.0 (including) 11.1.0 (including)
Big-ip_webaccelerator F5 11.2.0 (including) 11.2.0 (including)
Big-ip_webaccelerator F5 11.2.1 (including) 11.2.1 (including)
Big-ip_webaccelerator F5 11.3.0 (including) 11.3.0 (including)
Big-iq_cloud F5 4.0.0 (including) 4.0.0 (including)
Big-iq_cloud F5 4.1.0 (including) 4.1.0 (including)
Big-iq_cloud F5 4.2.0 (including) 4.2.0 (including)
Big-iq_cloud F5 4.3.0 (including) 4.3.0 (including)
Big-iq_device F5 4.2.0 (including) 4.2.0 (including)
Big-iq_device F5 4.3.0 (including) 4.3.0 (including)
Big-iq_security F5 4.0.0 (including) 4.0.0 (including)
Big-iq_security F5 4.1.0 (including) 4.1.0 (including)
Big-iq_security F5 4.2.0 (including) 4.2.0 (including)
Big-iq_security F5 4.3.0 (including) 4.3.0 (including)
Enterprise_manager F5 2.1.0 (including) 2.1.0 (including)
Enterprise_manager F5 2.2.0 (including) 2.2.0 (including)
Enterprise_manager F5 2.3.0 (including) 2.3.0 (including)
Enterprise_manager F5 3.0.0 (including) 3.0.0 (including)
Enterprise_manager F5 3.1.0 (including) 3.1.0 (including)
Enterprise_manager F5 3.1.1 (including) 3.1.1 (including)
Firepass F5 6.0.0 (including) 6.0.0 (including)
Firepass F5 6.0.1 (including) 6.0.1 (including)
Firepass F5 6.0.2 (including) 6.0.2 (including)
Firepass F5 6.0.3 (including) 6.0.3 (including)
Firepass F5 6.1.0 (including) 6.1.0 (including)
Firepass F5 7.0.0 (including) 7.0.0 (including)

Potential Mitigations

References