CVE-2014-2928

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/05/2014
Last modified:
12/04/2025

Description

The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.4:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.5:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.6:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.7:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:9.4.8:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:10.1.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:10.2.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:10.2.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:10.2.2:*:*:*:*:*:*:*