Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:F5 Local Security Checks
Title:F5 BIG-IP - privilege escalation vulnerability CVE-2014-3220
Summary:The remote host is missing a security patch.
The remote host is missing a security patch.

Vulnerability Insight:
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/. (CVE-2014-3220)

Vulnerability Impact:
An authenticated user with limited access may be able to gain administrative access to the system.

See the referenced vendor advisory for a solution.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-2937
Common Vulnerability Exposure (CVE) ID: CVE-2014-3220
BugTraq ID: 67191
BugTraq ID: 67227
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2022 E-Soft Inc. All rights reserved.