← Back

CVE-2014-2928

nvd nist
Published: May 12, 2014Modified: May 6, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:H/Au:S/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.

Affected (86)

9 products
Big Ip Webaccelerator
Big Ip Local Traffic Manager
Big Ip Protocol Security Module
Big Ip Link Controller
Big Ip Global Traffic Manager
Big Ip Wan Optimization Manager
Big Ip Access Policy Manager
Big Ip Edge Gateway
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 10.0.0
Version 10.0.1
Version 10.1.0
Version 10.2.0
Version 10.2.1
Version 10.2.2
Version 10.2.3
Version 10.2.4
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Version 11.3.0
Version 9.4.0
Version 9.4.1
Version 9.4.2
Version 9.4.3
Version 9.4.4
Version 9.4.5
Version 9.4.6
Version 9.4.7
Version 9.4.8
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 10.0.0
Version 10.0.1
Version 10.1.0
Version 10.2.0
Version 10.2.1
Version 10.2.2
Version 11.0.0
Configuration C
19 vulnerable
Configuration D
7 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 10.0.0
Version 10.0.1
Version 10.1.0
Version 10.2.0
Version 10.2.1
Version 10.2.2
Version 11.0.0
Configuration E
7 vulnerable
Configuration F
7 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 10.0.0
Version 10.0.1
Version 10.1.0
Version 10.2.0
Version 10.2.1
Version 10.2.2
Version 11.0.0
Configuration G
7 vulnerable
Configuration H
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 10.1.0
Version 10.2.0
Version 10.2.1
Version 10.2.2
Version 11.0.0
Configuration I
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 10.1.0
Version 10.2.0
Version 10.2.1
Version 10.2.2
Version 11.0.0

References (8)

Source: cret@cert.org
Exploit
Source: cret@cert.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.