Vulnerability Name: CVE-2014-2928 (CCN-93015) Assigned: 2014-05-07 Published: 2014-05-07 Updated: 2015-11-20 Summary: The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request. Per: http://cwe.mitre.org/data/definitions/77.html "CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')" CVSS v3 Severity: 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 7.1 High (CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C )5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P )5.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-Other Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2014-2928 Source: FULLDISC Type: UNKNOWN20140507 Moar F5 fun in iControl API Source: CONFIRM Type: Vendor Advisoryhttp://support.f5.com/kb/en-us/solutions/public/15000/200/sol15220.html Source: CCN Type: sol15220iControl vulnerability CVE-2014-2928 Source: EXPLOIT-DB Type: Exploit34927 Source: OSVDB Type: UNKNOWN106728 Source: CCN Type: OSVDB ID: 106728BIG-IP Multiple Products iControl Unspecified Command Execution Source: CCN Type: BID-67278Multiple F5 BIG-IP Products CVE-2014-2928 Remote Command Injection Vulnerability Source: XF Type: UNKNOWNbigip-icontrol-cve20142928-command-exec(93015) Source: CCN Type: Packet Storm Security [05-07-2014]F5 iControl Remote Command Execution Source: CCN Type: Packet Storm Security [10-08-2014]F5 iControl Remote Root Command Execution Source: EXPLOIT-DB Type: EXPLOITOffensive Security Exploit Database [10-09-2014] Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_webaccelerator:9.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.6:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.7:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.8:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.3.0:*:*:*:*:*:*:* Configuration 2 :cpe:/a:f5:big-ip_local_traffic_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.0.0:*:*:*:*:*:*:* Configuration 3 :cpe:/a:f5:big-ip_protocol_security_module:9.4.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:9.4.6:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:9.4.7:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:9.4.8:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.1:*:*:*:*:*:*:* Configuration 4 :cpe:/a:f5:big-ip_link_controller:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.0.0:*:*:*:*:*:*:* Configuration 5 :cpe:/a:f5:big-ip_application_security_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.0.0:*:*:*:*:*:*:* Configuration 6 :cpe:/a:f5:big-ip_global_traffic_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.0.0:*:*:*:*:*:*:* Configuration 7 :cpe:/a:f5:big-ip_wan_optimization_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.0.0:*:*:*:*:*:*:* Configuration 8 :cpe:/a:f5:big-ip_access_policy_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.0.0:*:*:*:*:*:*:* Configuration 9 :cpe:/a:f5:big-ip_edge_gateway:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:f5:big-ip:11.2.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip webaccelerator 9.4.0
f5 big-ip webaccelerator 9.4.1
f5 big-ip webaccelerator 9.4.2
f5 big-ip webaccelerator 9.4.3
f5 big-ip webaccelerator 9.4.4
f5 big-ip webaccelerator 9.4.5
f5 big-ip webaccelerator 9.4.6
f5 big-ip webaccelerator 9.4.7
f5 big-ip webaccelerator 9.4.8
f5 big-ip webaccelerator 10.0.0
f5 big-ip webaccelerator 10.0.1
f5 big-ip webaccelerator 10.1.0
f5 big-ip webaccelerator 10.2.0
f5 big-ip webaccelerator 10.2.1
f5 big-ip webaccelerator 10.2.2
f5 big-ip webaccelerator 10.2.3
f5 big-ip webaccelerator 10.2.4
f5 big-ip webaccelerator 11.0.0
f5 big-ip webaccelerator 11.1.0
f5 big-ip webaccelerator 11.2.0
f5 big-ip webaccelerator 11.2.1
f5 big-ip webaccelerator 11.3.0
f5 big-ip local traffic manager 10.0.0
f5 big-ip local traffic manager 10.0.1
f5 big-ip local traffic manager 10.1.0
f5 big-ip local traffic manager 10.2.0
f5 big-ip local traffic manager 10.2.1
f5 big-ip local traffic manager 10.2.2
f5 big-ip local traffic manager 11.0.0
f5 big-ip protocol security module 9.4.5
f5 big-ip protocol security module 9.4.6
f5 big-ip protocol security module 9.4.7
f5 big-ip protocol security module 9.4.8
f5 big-ip protocol security module 10.0.0
f5 big-ip protocol security module 10.0.1
f5 big-ip protocol security module 10.1.0
f5 big-ip protocol security module 10.2.0
f5 big-ip protocol security module 10.2.1
f5 big-ip protocol security module 10.2.2
f5 big-ip protocol security module 10.2.3
f5 big-ip protocol security module 10.2.4
f5 big-ip protocol security module 11.0.0
f5 big-ip protocol security module 11.1.0
f5 big-ip protocol security module 11.2.0
f5 big-ip protocol security module 11.2.1
f5 big-ip protocol security module 11.3.0
f5 big-ip protocol security module 11.4.0
f5 big-ip protocol security module 11.4.1
f5 big-ip link controller 10.0.0
f5 big-ip link controller 10.0.1
f5 big-ip link controller 10.1.0
f5 big-ip link controller 10.2.0
f5 big-ip link controller 10.2.1
f5 big-ip link controller 10.2.2
f5 big-ip link controller 11.0.0
f5 big-ip application security manager 10.0.0
f5 big-ip application security manager 10.0.1
f5 big-ip application security manager 10.1.0
f5 big-ip application security manager 10.2.0
f5 big-ip application security manager 10.2.1
f5 big-ip application security manager 10.2.2
f5 big-ip application security manager 11.0.0
f5 big-ip global traffic manager 10.0.0
f5 big-ip global traffic manager 10.0.1
f5 big-ip global traffic manager 10.1.0
f5 big-ip global traffic manager 10.2.0
f5 big-ip global traffic manager 10.2.1
f5 big-ip global traffic manager 10.2.2
f5 big-ip global traffic manager 11.0.0
f5 big-ip wan optimization manager 10.0.0
f5 big-ip wan optimization manager 10.0.1
f5 big-ip wan optimization manager 10.1.0
f5 big-ip wan optimization manager 10.2.0
f5 big-ip wan optimization manager 10.2.1
f5 big-ip wan optimization manager 10.2.2
f5 big-ip wan optimization manager 11.0.0
f5 big-ip access policy manager 10.1.0
f5 big-ip access policy manager 10.2.0
f5 big-ip access policy manager 10.2.1
f5 big-ip access policy manager 10.2.2
f5 big-ip access policy manager 11.0.0
f5 big-ip edge gateway 10.1.0
f5 big-ip edge gateway 10.2.0
f5 big-ip edge gateway 10.2.1
f5 big-ip edge gateway 10.2.2
f5 big-ip edge gateway 11.0.0
f5 big-ip 11.2.1