peter bassill · operator
$ cve CVE-2014-2927 JSON

CVE-2014-2927 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 7.9% (pctl 95)

Patch early

A public exploit exists.

Description

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when configured in failover mode, does not require authentication, which allows remote attackers to read or write to arbitrary files via a cmi request to the ConfigSync IP address.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS7.92% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2014-10-15
Last modified2026-06-17

Affected (19)

VendorProduct
f5arx
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip edge gateway
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
f5big-ip protocol security module
f5big-ip wan optimization manager
f5big-ip webaccelerator
f5big-iq cloud
f5big-iq device
f5big-iq security
f5enterprise manager
f5firepass

Public exploits

SourceTitleDate
exploit-dbF5 Big-IP - rsync Access2014-08-29

References

→ the Explorer  ·  watch your stack  ·  NVD