| Vulnerability Name: | CVE-2014-3220 (CCN-93007) | ||||||||
| Assigned: | 2014-05-01 | ||||||||
| Published: | 2014-05-01 | ||||||||
| Updated: | 2014-05-23 | ||||||||
| Summary: | F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 8.2 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:F/RL:U/RC:UR)
6.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-255 | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-3220 Source: CCN Type: Full Disclosure Mailing List: Thu 1 May 2014 F5 BIG-IQ authed arbitrary user password change Source: FULLDISC Type: UNKNOWN 20140501 F5 BIG-IQ authed arbitrary user password change Source: FULLDISC Type: Exploit 20140502 Re: F5 BIG-IQ authed arbitrary user password change Source: FULLDISC Type: UNKNOWN 20140504 Re: F5 BIG-IQ authed arbitrary user password change Source: SECUNIA Type: UNKNOWN 58440 Source: CONFIRM Type: UNKNOWN http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15229.html Source: MISC Type: UNKNOWN http://volatile-minds.blogspot.com/2014/05/f5-big-iq-v41020130-authenticated.html Source: EXPLOIT-DB Type: UNKNOWN 33143 Source: CCN Type: OSVDB ID: 106532 F5 BIG-IQ /mgmt/shared/authz/users/ name Parameter Manipulation Remote Privilege Escalation Source: BID Type: UNKNOWN 67191 Source: CCN Type: BID-67191 F5 Networks BIG-IQ Remote Privilege Escalation Vulnerability Source: BID Type: UNKNOWN 67227 Source: CCN Type: BID-67227 Multiple F5 BIG-IQ Products Configuration Utility Access Control Security Bypass Vulnerability Source: XF Type: UNKNOWN f5-bigiq-cve20143220-priv-esc(93007) Source: CCN Type: F5 Web site BIG-IQ Source: MISC Type: Exploit https://gist.github.com/brandonprry/2e73acd63094fa2a4f63 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||