Vulnerability CVE-2014-6032


Published: 2014-11-01   Modified: 2014-11-02

Description:
Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 and 10.0.0 through 10.2.4, AAM 11.4.0 through 11.6.0, ARM 11.3.0 through 11.6.0, Analytics 11.0.0 through 11.6.0, APM and Edge Gateway 11.0.0 through 11.6.0 and 10.1.0 through 10.2.4, PEM 11.3.0 through 11.6.0, PSM 11.0.0 through 11.4.1 and 10.0.0 through 10.2.4, and WOM 11.0.0 through 11.3.0 and 10.0.0 through 10.2.4 and Enterprise Manager 3.0.0 through 3.1.1 and 2.1.0 through 2.3.0 allow remote authenticated users to read arbitrary files and cause a denial of service via a crafted request, as demonstrated using (1) viewList or (2) deal elements.

See advisories in our WLB2 database:
Topic
Author
Date
High
F5 Networks Big-IP XML External Entity Injection
Portcullis Advis...
30.10.2014

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.5/10
4.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
Partial
Affected software
F5 -> Big-ip application security manager 
F5 -> Big-ip advanced firewall manager 
F5 -> Big-ip analytics 
F5 -> Big-ip application acceleration manager 
F5 -> Big-ip edge gateway 
F5 -> Big-ip global traffic manager 
F5 -> Big-ip link controller 
F5 -> Big-ip local traffic manager 
F5 -> Big-ip policy enforcement manager 
F5 -> Big-ip protocol security module 
F5 -> Big-ip wan optimization manager 
F5 -> Big-ip webaccelerator 
F5 -> Enterprise manager 

 References:
http://packetstormsecurity.com/files/128915/F5-Big-IP-11.3.0.39.0-XML-External-Entity-Injection-1.html
http://seclists.org/fulldisclosure/2014/Oct/128
http://seclists.org/fulldisclosure/2014/Oct/129
http://seclists.org/fulldisclosure/2014/Oct/130
http://www.securityfocus.com/bid/70834
http://www.securitytracker.com/id/1031144
http://www.securitytracker.com/id/1031145
https://exchange.xforce.ibmcloud.com/vulnerabilities/98402
https://exchange.xforce.ibmcloud.com/vulnerabilities/98403
https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15605.html
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-6032/
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-6033/

Copyright 2024, cxsecurity.com

 

Back to Top