← All CVEs

CVE-2014-3220

high · 9

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.

9
CVSS
11.0%
EPSS (exploit prob.)
96th
EPSS percentile
2014-05-05
Published

AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

CWE-255

Affected products

VendorProductAffected versions
f5big-iq4.1.0.2013.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-3220