PT-2014-4961 · F5 · Enterprise Manager+1
Publicado
2014-10-15
·
Atualizado
2015-01-26
·
CVE-2014-2927
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 11.2.1 through 11.6.0 before 11.6.0
F5 BIG-IP version 11.5.1 before HF3
F5 BIG-IP version 11.5.0 before HF4
F5 BIG-IP version 11.4.1 before HF4
F5 BIG-IP version 11.4.0 before HF7
F5 BIG-IP version 11.3.0 before HF9
F5 BIG-IP version 11.2.1 before HF11
Enterprise Manager versions 3.x before 3.1.1 HF2
Description
The issue allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address, due to the lack of authentication requirement in the rsync daemon when configured in failover mode.
Recommendations
For F5 BIG-IP versions 11.2.1 through 11.6.0 before 11.6.0, update to version 11.6.0 or later.
For F5 BIG-IP version 11.5.1 before HF3, apply Hotfix 3.
For F5 BIG-IP version 11.5.0 before HF4, apply Hotfix 4.
For F5 BIG-IP version 11.4.1 before HF4, apply Hotfix 4.
For F5 BIG-IP version 11.4.0 before HF7, apply Hotfix 7.
For F5 BIG-IP version 11.3.0 before HF9, apply Hotfix 9.
For F5 BIG-IP version 11.2.1 before HF11, apply Hotfix 11.
For Enterprise Manager versions 3.x before 3.1.1 HF2, update to version 3.1.1 HF2 or later.
As a temporary workaround, consider restricting access to the ConfigSync IP address to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Enterprise Manager
F5 Big-Ip