[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-3220Date: (C)2014-05-10   (M)2023-12-22


F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.0
Exploit Score: 8.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://seclists.org/fulldisclosure/2014/May/10
http://seclists.org/fulldisclosure/2014/May/11
http://seclists.org/fulldisclosure/2014/May/16
EXPLOIT-DB-33143
SECUNIA-58440
BID-67191
BID-67227
http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15229.html
http://volatile-minds.blogspot.com/2014/05/f5-big-iq-v41020130-authenticated.html
https://gist.github.com/brandonprry/2e73acd63094fa2a4f63

CWE    1
CWE-255

© SecPod Technologies