ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Firms Urged to Patch as Attackers Exploit Critical F5 Bugs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-22986
Unauthenticated RCE in F5 BIG-IP and BIG-IQ iControl REST

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability (CWE-863, improper authorization check) in the iControl REST interface. An unauthenticated attacker with network access to the REST endpoint can send crafted requests to execute arbitrary system commands, create or delete files, and disable services on the appliance or virtual instance. Successful exploitation effectively gives the attacker command-level control of the underlying F5 system, which is sufficient for account creation, persistence, lateral movement, and ransomware staging. Any organization running affected BIG-IP or BIG-IQ releases is exposed, particularly where the management interface or iControl REST is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, EPSS places the 30-day exploitation probability at 99.9% (top percentile), though no public PoC is cataloged.

Do: Upgrade BIG-IP and BIG-IQ to the fixed releases identified in F5's advisory (K03051234) on an urgent basis, since exploitation is in the wild and ransomware actors use this flaw. Until patched, restrict network access to the management interface and iControl REST to trusted administration networks. Because ransomware use is known, review affected devices for indicators of compromise such as unexpected commands, created or deleted files, and disabled services.

9.8100% KEV ransomware PoC ×2
  • F5 BIG-IP
  • F5 BIG-IQ Centralized Management
largetens of thousands of internet-exposed BIG-IP management interfaces (public scan counts at disclosure), within a total installed base of hundreds of thousands…
CVE-2021-22987
+3 in the same advisory: …22989 …22988 …22990
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

NVD description · AI analysis pending
9.9
group max
14%
  • f5 big-ip access policy manager
  • f5 big-ip advanced firewall manager
  • f5 big-ip advanced web application firewall
  • +1 more
Full article370 words · extracted from infosecurity-magazine.com · click to collapse

Security experts are urging F5 customers to patch a critical vulnerability in the vendor's BIG-IP and BIG-IQ networking products after warning of mass exploitation attempts in the wild.

CVE-2021-22986 is a flaw in the products’ REST-based iControl management interface which could allow for authentication bypass and remote code execution.

With a CVSS rating of 9.8, it was patched on March 10 along with several other bugs that could be chained in attacks. These are: CVE-2021-22987, CVE-2021-22988, CVE-2021-22989 and CVE-2021-22990.

Although no public exploit was known about at the time of patching, a week later researchers began to post PoC code online after reverse engineering an F5 patch.

NCC Group warned on Friday that as the REST API in question is designed to facilitate remote administration, an attacker could choose from multiple endpoints in an organization which ones to target.

“Starting this week and especially in the last 24 hours (March 18th, 2021) we have observed multiple exploitation attempts against our honeypot infrastructure. This knowledge, combined with having reproduced the full exploit-chain we assess that a public exploit is likely to be available in the public domain soon,” it said.

“NCC Group believes it is in the best interests of all to release our internal notes and detection logic to prevent further harm once public exploits become available.”

Networking firm F5 serves some of the world’s biggest organizations, including tech and financial services giants, so both state actors and financially motivated cyber-criminals will be keen to probe for unpatched endpoints.

The US Cybersecurity and Infrastructure Security Agency (CISA) has already sounded the alarm, urging customers to patch the issue promptly.

However, as we’ve seen with the recent Exchange Server attacks, many organizations are finding it challenging to fix or mitigate issues quickly, even if official updates are available.

Vdoo CTO, Asaf Karas, argued that the threat landscape for connected products has become complicated and multi-dimensional.

“Networking devices such as load balancers and access gateways are desirable targets for threat actors, as they’re used to control the traffic in and out of large corporate networks, government agencies, data centers and across ISP infrastructure,” he added.

“Once inside the network, attackers can move laterally to take control of critical resources and data.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/firms-urged-to-patch-exploit/