← Back

CVE-2015-3628

nvd nist
Published: Dec 7, 2015Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0 through 11.4.1, Enterprise Manager 3.1.0 through 3.1.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote authenticated users with the "Resource Administrator" role to gain privileges via an iCall (1) script or (2) handler in a SOAP request to iControl/iControlPortal.cgi.

Affected (97)

18 products
Big Iq Security
Big Ip Wan Optimization Manager
Big Iq Adc
Big Ip Global Traffic Manager
Big Iq Device
Big Ip Edge Gateway
Big Ip Local Traffic Manager
Big Ip Access Policy Manager
Big Ip Policy Enforcement Manager
Big Iq Cloud
Big Ip Analytics
Big Ip Protocol Security Module
Big Ip Webaccelerator
Big Ip Link Controller
Big Ip Enterprise Manager
Big Ip Advanced Firewall Manager
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Configuration B
7 vulnerable
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.5.0
Configuration E
8 vulnerable
Configuration F
8 vulnerable
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3.0
Configuration I
8 vulnerable
Configuration J
8 vulnerable
Configuration K
8 vulnerable
Configuration L
6 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Configuration M
8 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.3.0
Version 11.4.0
Version 11.4.1
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.5.3
Version 11.6.0
Configuration N
3 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.3.0
Version 11.4.0
Version 11.4.1
Configuration O
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3.0
Configuration P
8 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.3.0
Version 11.4.0
Version 11.4.1
Version 11.5.0
Version 11.5.1
Version 11.5.2
Version 11.5.3
Version 11.6.0
Configuration Q
3 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 3.0.0
Version 3.1.0
Version 3.1.1
Configuration R
8 vulnerable

Related CWEs

Timeline

No history available yet.