CVE-2014-9326
Last modified
CVE-2014-9326 is a vulnerability of currently unknown severity. The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificates, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificates, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Application Acceleration Manager | 11.5.0 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.1 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.2 |
| F5 | Big-Ip Application Acceleration Manager | 11.6.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.3.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.4.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.4.1 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.2 |
| F5 | Big-Ip Policy Enforcement Manager | 11.6.0 |
| F5 | Big-Ip Policy Enforcement Manager11.5.1 | All versions |
| F5 | Big-Ip Global Traffic Manager | 11.5.0 |
| F5 | Big-Ip Global Traffic Manager | 11.5.1 |
| F5 | Big-Ip Global Traffic Manager | 11.5.2 |
| F5 | Big-Ip Global Traffic Manager | 11.6.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.1 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.2 |
| F5 | Big-Ip Advanced Firewall Manager | 11.6.0 |
| F5 | Big-Ip Local Traffic Manager | 11.5.0 |
| F5 | Big-Ip Local Traffic Manager | 11.5.1 |
| F5 | Big-Ip Local Traffic Manager | 11.5.2 |
| F5 | Big-Ip Local Traffic Manager | 11.6.0 |
| F5 | Big-Ip Application Security Manager | 11.5.0 |
| F5 | Big-Ip Application Security Manager | 11.5.1 |
| F5 | Big-Ip Application Security Manager | 11.5.2 |
| F5 | Big-Ip Application Security Manager | 11.6.0 |
| F5 | Big-Ip Link Controller | 11.5.0 |
| F5 | Big-Ip Link Controller | 11.5.1 |
| F5 | Big-Ip Link Controller | 11.5.2 |
| F5 | Big-Ip Link Controller | 11.6.0 |
| F5 | Big-Ip Access Policy Manager | 11.5.0 |
| F5 | Big-Ip Access Policy Manager | 11.5.1 |
| F5 | Big-Ip Access Policy Manager | 11.5.2 |
| F5 | Big-Ip Access Policy Manager | 11.6.0 |
| F5 | Big-Ip Analytics | 11.5.0 |
| F5 | Big-Ip Analytics | 11.5.1 |
| F5 | Big-Ip Analytics | 11.5.2 |
| F5 | Big-Ip Analytics | 11.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9326?
How severe is CVE-2014-9326?
How do I fix CVE-2014-9326?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-9319The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c …
- CVE-2014-9320SAP BusinessObjects Edge 4.1 allows remote attackers to obta…9.8
- CVE-2014-9322arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5…7.8
- CVE-2014-9323The xdr_status_vector function in Firebird before 2.1.7 and …
- CVE-2014-9324The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, …
- CVE-2014-9325Multiple cross-site scripting (XSS) vulnerabilities in TWiki…
- CVE-2014-9328ClamAV before 0.98.6 allows remote attackers to have unspeci…
- CVE-2014-9330Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0…
- CVE-2014-9331Cross-site request forgery (CSRF) vulnerability in ZOHO Mana…
- CVE-2014-9334Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-9335Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-9336Multiple cross-site request forgery (CSRF) vulnerabilities i…
Are you affected by CVE-2014-9326?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
