Vulnerability record · CVE-2015-3628 · published 7 December 2015
CVE-2015-3628: F5 BIG-IP iControl iCall privilege escalation to root
F5 · Big Iq Security
The iControl API in multiple F5 BIG-IP and BIG-IQ products fails to properly restrict the iCall script and handler functionality, letting a remote authenticated user with the Resource Administrator role execute privileged operations. Because that role is meant to be limited, the flaw breaks the intended privilege boundary and can yield full control of the affected appliance.
Description
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0 through 11.4.1, Enterprise Manager 3.1.0 through 3.1.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote authenticated users with the "Resource Administrator" role to gain privileges via an iCall (1) script or (2) handler in a SOAP request to iControl/iControlPortal.cgi.
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityA network-reachable privilege escalation with public exploit code and very high EPSS, though it requires an authenticated Resource Administrator account and is not in KEV.
What it is
The iControl API in multiple F5 BIG-IP and BIG-IQ products fails to properly restrict the iCall script and handler functionality, letting a remote authenticated user with the Resource Administrator role execute privileged operations. Because that role is meant to be limited, the flaw breaks the intended privilege boundary and can yield full control of the affected appliance.
Impact
An attacker with a low-privileged Resource Administrator account gains elevated privileges, up to root-level command execution on the device, compromising the confidentiality, integrity and availability of the managed traffic and configuration.
Attack surface
Reached over the network through a SOAP request to iControl/iControlPortal.cgi using an iCall script or handler. Authentication is required, but only at the Resource Administrator role, and no user interaction is needed.
Exploitation
Public exploit code exists (Packet Storm, Rapid7, Exploit-DB references tagged Exploit), and EPSS is 0.68483 (99.3rd percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the F5 fixed versions: 11.5.3 HF2 or later for 11.3.0-11.5.x, and 11.6.0 HF6 or later for 11.6.0, per vendor advisory SOL16728.
- Restrict and audit accounts holding the Resource Administrator role; remove it from users who do not need it.
- Limit network access to the iControl/iControlPortal.cgi management interface to trusted administrative networks.
- Monitor and alert on unexpected iCall script or handler creation and on SOAP requests to iControl endpoints.
- If patching is delayed, disable or tightly control iCall functionality where operationally feasible.
Detection
- Audit iControl SOAP requests to iControlPortal.cgi for iCall script or handler creation, especially from Resource Administrator accounts.
- Monitor for new or modified iCall scripts and handlers on BIG-IP/BIG-IQ systems.
- Alert on processes or commands spawned by the iControl service that indicate privilege escalation or shell execution.
- Review authentication logs for Resource Administrator logins from unusual sources or at unusual times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3628 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3628), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.