ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are bypassing F5 BIG-IP RCE mitigation - you might want to patch after all

highVulnerability exploited in the wildimportance 60CVE-2020-5902

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-5902
Unauthenticated RCE via path traversal in F5 BIG-IP TMUI

CVE-2020-5902 is a critical, unauthenticated remote code execution flaw in the F5 BIG-IP Traffic Management User Interface (TMUI), the appliance's web management console, rooted in a directory/path traversal issue (CWE-22) in undisclosed TMUI pages. It is triggered by sending crafted HTTP(S) requests to the management interface — classically path-traversal URLs beneath the TMUI application on the management port — which lets an attacker bypass authentication, read or delete arbitrary files, and execute commands without credentials. Successful exploitation yields full control of the BIG-IP system, which attackers can use to pivot into networks the appliance fronts, maintain persistence, and deploy ransomware. Any organization running an affected F5 BIG-IP appliance or virtual edition whose TMUI is reachable, or whose management network can be reached, is exposed; F5's installed base spans large enterprises and service providers, so the footprint is broad. Exploitation is confirmed in the wild: the flaw was mass-scanned and exploited within days of its July 2020 disclosure, it is listed in CISA KEV with known ransomware use, and EPSS assigns a ~100% probability of exploitation within 30 days.

Do: Patch immediately using F5's advisory K52145254 — upgrade BIG-IP to a fixed release per the vendor's version matrix, since CISA's required action is applying vendor updates. Until patched, restrict TMUI/management-interface access to trusted source IPs or a VPN (or disable TMUI if unused) and apply F5's published interim workaround. Because ransomware use is confirmed, hunt for indicators of compromise on both patched and unpatched appliances (unexpected files, webshells, modified login pages, new accounts or scheduled tasks) before treating systems as clean.

9.8100% KEV ransomware PoC ×8
  • F5 BIG-IP
mass≈100,000–300,000 internet-exposed BIG-IP TMUI endpoints, with a far larger internal installed base
Full article361 words · extracted from helpnetsecurity.com · click to collapse

Attackers are bypassing a mitigation for the BIG-IP TMUI RCE vulnerability (CVE-2020-5902) originally provided by F5 Networks, NCC Group’s Research and Intelligence Fusion Team has discovered.

On CVE-2020-5902 (K52145254) @TeamAresSec reported publicly at 18:24 the mitigation could be bypassed, we saw it used in the wild at 12:39 for the first time – upgrade don't mitigate – https://t.co/sSr4JIZwu3 pic.twitter.com/PMfG0rCpyQ

— NCC Group Infosec (@NCCGroupInfosec) July 7, 2020

“Early data made available to us, as of 08:05 on July 8, 2020, is showing of ~10,000 Internet exposed F5 devices that ~6,000 were made potentially vulnerable again due to the bypass,” they warned.

F5 Networks has updated the security advisory to reflect this discovery and to provide an updated version of the mitigation. The advisory has also been updated with helpful notes regarding the impact of the flaw, the various mitigations, as well as indicators of compromise.

CVE-2020-5902 exploitation attempts

CVE-2020-5902 was discovered and privately disclosed by Positive Technologies researcher Mikhail Klyuchnikov.

F5 Networks released patches and published mitigations last Wednesday and PT followed with more information.

Security researchers were quick to set up honeypots to detect exploitation attempts and, a few dats later, after several exploits had been made public, they started.

Some were reconnaissance attempts, some tried to deliver backdoors, DDoS bots, coin miners, web shells, etc. Some were attempts to scrape admin credentials off vulnerable devices in an automated fashion.

There’s also a Metasploit module for CVE-2020-5902 exploitation available (and in use).

What now?

Any organization that applied the original, incomplete mitigation instead of patching their F5 BIG-IP boxes should take action again:

🚨 For those orgs who applied the F5 BIG-IP and BIG-IQ mitigation rather than patching 🚨

there’s a bypass to the mitigation being used in the wild now.

So you either need to emergency patch or emergency change request the mitigation config. https://t.co/gltioNteKR https://t.co/sfebJ3UcE6

— Kevin Beaumont (@GossiTheDog) July 8, 2020

this is not good. If you applied the workaround… you need to patch! (or finally isolate your admin interface) https://t.co/RlWb61qZoh

— SANS ISC (@sans_isc) July 8, 2020

They should also check whether their devices have been compromised in the interim.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/07/08/bypassing-f5-big-ip-rce-mitigation/