← Back

CVE-2014-9326

nvd nist
Published: May 12, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificates, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

Affected (39)

10 products
Big Ip Policy Enforcement Manager
Big Ip Global Traffic Manager
Big Ip Advanced Firewall Manager
Big Ip Local Traffic Manager
Big Ip Link Controller
Big Ip Analytics
Big Ip Access Policy Manager
Configuration A
4 vulnerable
Configuration B
7 vulnerable
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0
Configuration I
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0
Configuration J
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.6.0

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.