← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-2927

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.

No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:7.92%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
f5 arx 6.0.0, 6.1.0, 6.1.1, 6.2.0, 6.3.0, 6.4.0
f5 big-ip_access_policy_manager 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_advanced_firewall_manager 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_analytics 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_application_acceleration_manager 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_application_security_manager 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_edge_gateway 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0
f5 big-ip_global_traffic_manager 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_link_controller 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_local_traffic_manager 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_policy_enforcement_manager 11.3.0, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.6.0
f5 big-ip_protocol_security_module 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0, 11.4.0, 11.4.1
f5 big-ip_wan_optimization_manager 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0
f5 big-ip_webaccelerator 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.3.0
f5 big-iq_cloud 4.0.0, 4.1.0, 4.2.0, 4.3.0
f5 big-iq_device 4.2.0, 4.3.0
f5 big-iq_security 4.0.0, 4.1.0, 4.2.0, 4.3.0
f5 enterprise_manager 2.1.0, 2.2.0, 2.3.0, 3.0.0, 3.1.0, 3.1.1
f5 firepass 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 7.0.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
7.920%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2014-04-21T00:00:00
Published2014-10-15T14:00:00
Patch Date2014-08-28
Last Updated2024-08-06T10:28:46

LINK COPIED TO CLIPBOARD