ZeroHour
The Recordpublished ()ingested

CISA urges F5 users to address 'critical' vulnerability in BIG

criticalVulnerabilityimportance 60CVE-2022-1388

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-1388
Unauthenticated RCE in F5 BIG-IP via Missing Authentication

F5 BIG-IP contains a critical missing-authentication flaw (CWE-306) in its iControl REST control plane: an unauthenticated attacker with network reachability to the management interface, or to self IPs exposing the REST service on TCP 443, can bypass authentication completely. By sending specially crafted HTTP requests, the attacker gains the ability to execute arbitrary code, create or delete files, and disable services, effectively achieving full takeover of the load balancer or security appliance and the traffic it handles. All F5 BIG-IP deployments running unpatched software are affected; the provided data does not enumerate exact version ranges, which are listed in F5's May 2022 security advisory. The flaw was added to CISA's KEV catalog on 2022-05-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), indicating active in-the-wild exploitation. No public proof-of-concept is catalogued in the provided data, but the KEV listing and known ransomware use confirm real-world attacks.

Do: Upgrade affected F5 BIG-IP systems to the fixed releases listed in F5's May 2022 security advisory (K23605340) immediately, prioritizing appliances whose management interface or self IPs on TCP 443 are reachable from untrusted networks; as an interim mitigation, block untrusted access to the management interface and the iControl REST service. Because this flaw is in CISA's KEV catalog with known ransomware use, also hunt for signs of compromise (unexpected files, disabled services, unknown persistence) on any system that was exposed before patching.

9.8100% KEV ransomware PoC ×4
  • F5 BIG-IP
large~10,000 internet-exposed BIG-IP systems (public scans at disclosure counted 8k-10k+), with a far larger installed base behind firewalls
Full article394 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency is urging F5 customers to address a vulnerability in BIG-IP products that could allow an attacker "to take control of an affected system."

The company also released an advisory about the bug, CVE-2022-1388, which could allow an attacker with access through the BIG-IP system's management port to execute arbitrary system commands, create or delete files, or disable services.

BIG-IP products — which include software and hardware — are used widely by companies to help keep their applications up and running. The CISA alert revolves around the iControl REST component, which helps manage interaction "between user or script and F5 device," according to the company.

The vulnerability — which F5 said it discovered internally — has a CVSS score of 9.8 out of 10, ranking it as "critical."

F5 said BIG-IP versions 16.1.0 to 16.1.2, 15.1.0 to 15.1.5, 14.1.0 to 14.1.4, 13.1.0 to 13.1.4, 12.1.0 to 12.1.6 and 11.6.1 to 11.6.5 are affected.

F5 published fixes for each version except for 12.1.0 to 12.1.6 and 11.6.1 to 11.6.5. It urged those using these versions to upgrade to a version with the fix. 

An F5 chart of affected versions. (F5)

The company released several mitigations that involve restricting access to iControl REST to only trusted networks or devices, thereby limiting the attack surface.

Vulcan Cyber’s Mike Parkin told The Record that industry best practices restrict access to management interfaces in general, which would make it difficult for an external attacker to reach the management interface and exploit this vulnerability.

A search on Shodan shows there are at least 15,890 BIG-IP products exposed to the internet, leaving them potentially vulnerable to CVE-2022-1388. There 3,770 vulnerable instances in the US, followed by 1,396 in China and 897 in India, according to Shodan.

Nicole Hoffman, senior cyberthreat intelligence analyst at Digital Shadows, said the critical vulnerability is particularly concerning because it can lead to complete system takeover. 

“It likely won't be long before ransomware groups and initial access brokers will start mass scanning for vulnerable devices,” Hoffman noted.  

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/f5-big-ip-alert-cisa