Rsync Daemon Vulnerability in F5 BIG-IP and Enterprise Manager
CVE-2014-2927
Currently unrated
Key Information:
- Vendor
F5
- Vendor
- CVE Published:
- 15 October 2014
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2014-2927?
The rsync daemon in F5 BIG-IP and Enterprise Manager, when configured in failover mode, does not require authentication for access. This flaw allows unauthorized remote attackers to read or modify files by sending crafted requests to the ConfigSync IP address, posing significant security risks to affected systems.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.