Rsync Daemon Vulnerability in F5 BIG-IP and Enterprise Manager
CVE-2014-2927

Currently unrated

Key Information:

Summary

The rsync daemon in F5 BIG-IP and Enterprise Manager, when configured in failover mode, does not require authentication for access. This flaw allows unauthorized remote attackers to read or modify files by sending crafted requests to the ConfigSync IP address, posing significant security risks to affected systems.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.