CVE-2014-9326 - CVE House
Back to Database
Status published Medium CVE-2014-9326

The automatic signature update functionality in the (1) Phone Home...

Vulnerability Description

The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificates, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9326

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

big-ip application acceleration manager, big-ip policy enforcement manager, big-ip policy enforcement manager11.5.1, big-ip global traffic manager, big-ip advanced firewall manager, big-ip local traffic manager, big-ip application security manager, big-ip link controller, big-ip access policy manager, big-ip analytics
Vulnerable Versions:
11.5.0, 11.5.1, 11.5.2, 11.6.0, 11.3.0, 11.4.0, 11.4.1

Timeline

Official Publish: May 12th, 2015
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.