First published: Mon May 05 2014(Updated: )
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IQ Device | =4.1.0.2013.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3220 is classified as a high severity vulnerability due to the potential for unauthorized password changes.
CVE-2014-3220 affects remote authenticated users of F5 BIG-IQ Cloud and Security versions 4.0.0 to 4.1.0.
To fix CVE-2014-3220, users should upgrade to a patched version of F5 BIG-IQ that addresses this vulnerability.
CVE-2014-3220 can lead to elevation of privilege attacks where a user can change the passwords of any other user within the system.
Yes, CVE-2014-3220 is exploitable remotely, provided the attacker has valid authentication credentials.