4.3
CVSSv2

CVE-2014-9326

Published: 12/05/2015 Updated: 03/01/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 up to and including 11.6.0, ASM 10.0.0 up to and including 11.6.0, and PEM 11.3.0 up to and including 11.6.0 and the (2) Call Home feature in ASM 10.0.0 up to and including 11.6.0 and PEM 11.3.0 up to and including 11.6.0 does not properly validate server SSL certificates, which allows remote malicious users to conduct man-in-the-middle attacks via a crafted certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip application acceleration manager 11.5.0

f5 big-ip application acceleration manager 11.5.1

f5 big-ip application acceleration manager 11.5.2

f5 big-ip application acceleration manager 11.6.0

f5 big-ip policy enforcement manager 11.5.0

f5 big-ip policy enforcement manager11.5.1

f5 big-ip policy enforcement manager 11.5.2

f5 big-ip policy enforcement manager 11.6.0

f5 big-ip policy enforcement manager 11.3.0

f5 big-ip policy enforcement manager 11.4.0

f5 big-ip policy enforcement manager 11.4.1

f5 big-ip global traffic manager 11.6.0

f5 big-ip global traffic manager 11.5.0

f5 big-ip global traffic manager 11.5.1

f5 big-ip global traffic manager 11.5.2

f5 big-ip advanced firewall manager 11.5.0

f5 big-ip advanced firewall manager 11.5.1

f5 big-ip advanced firewall manager 11.5.2

f5 big-ip advanced firewall manager 11.6.0

f5 big-ip local traffic manager 11.5.2

f5 big-ip local traffic manager 11.6.0

f5 big-ip local traffic manager 11.5.0

f5 big-ip local traffic manager 11.5.1

f5 big-ip application security manager 11.5.1

f5 big-ip application security manager 11.5.2

f5 big-ip application security manager 11.5.0

f5 big-ip application security manager 11.6.0

f5 big-ip link controller 11.6.0

f5 big-ip link controller 11.5.2

f5 big-ip link controller 11.5.1

f5 big-ip link controller 11.5.0

f5 big-ip access policy manager 11.5.0

f5 big-ip access policy manager 11.6.0

f5 big-ip access policy manager 11.5.2

f5 big-ip access policy manager 11.5.1

f5 big-ip analytics 11.6.0

f5 big-ip analytics 11.5.0

f5 big-ip analytics 11.5.2

f5 big-ip analytics 11.5.1