Threat actors start attacking F5 devices using recent vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5902 | Unauthenticated RCE via path traversal in F5 BIG-IP TMUI CVE-2020-5902 is a critical, unauthenticated remote code execution flaw in the F5 BIG-IP Traffic Management User Interface (TMUI), the appliance's web management console, rooted in a directory/path traversal issue (CWE-22) in undisclosed TMUI pages. It is triggered by sending crafted HTTP(S) requests to the management interface — classically path-traversal URLs beneath the TMUI application on the management port — which lets an attacker bypass authentication, read or delete arbitrary files, and execute commands without credentials. Successful exploitation yields full control of the BIG-IP system, which attackers can use to pivot into networks the appliance fronts, maintain persistence, and deploy ransomware. Any organization running an affected F5 BIG-IP appliance or virtual edition whose TMUI is reachable, or whose management network can be reached, is exposed; F5's installed base spans large enterprises and service providers, so the footprint is broad. Exploitation is confirmed in the wild: the flaw was mass-scanned and exploited within days of its July 2020 disclosure, it is listed in CISA KEV with known ransomware use, and EPSS assigns a ~100% probability of exploitation within 30 days. Do: Patch immediately using F5's advisory K52145254 — upgrade BIG-IP to a fixed release per the vendor's version matrix, since CISA's required action is applying vendor updates. Until patched, restrict TMUI/management-interface access to trusted source IPs or a VPN (or disable TMUI if unused) and apply F5's published interim workaround. Because ransomware use is confirmed, hunt for indicators of compromise on both patched and unpatched appliances (unexpected files, webshells, modified login pages, new accounts or scheduled tasks) before treating systems as clean. | 9.8 | 100% | KEV ransomware PoC ×8 |
| mass≈100,000–300,000 internet-exposed BIG-IP TMUI endpoints, with a far larger internal installed base | |
| CVE-2021-22986 | Unauthenticated RCE in F5 BIG-IP and BIG-IQ iControl REST F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability (CWE-863, improper authorization check) in the iControl REST interface. An unauthenticated attacker with network access to the REST endpoint can send crafted requests to execute arbitrary system commands, create or delete files, and disable services on the appliance or virtual instance. Successful exploitation effectively gives the attacker command-level control of the underlying F5 system, which is sufficient for account creation, persistence, lateral movement, and ransomware staging. Any organization running affected BIG-IP or BIG-IQ releases is exposed, particularly where the management interface or iControl REST is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, EPSS places the 30-day exploitation probability at 99.9% (top percentile), though no public PoC is cataloged. Do: Upgrade BIG-IP and BIG-IQ to the fixed releases identified in F5's advisory (K03051234) on an urgent basis, since exploitation is in the wild and ransomware actors use this flaw. Until patched, restrict network access to the management interface and iControl REST to trusted administration networks. Because ransomware use is known, review affected devices for indicators of compromise such as unexpected commands, created or deleted files, and disabled services. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed BIG-IP management interfaces (public scan counts at disclosure), within a total installed base of hundreds of thousands… |
Full article589 words · extracted from therecord.media · click to collapse
Multiple hacking groups have started attacking F5 networking devices after the publication of proof-of-concept exploit code online for a recent critical vulnerability the vendor patched last week. Tracked as CVE-2021-22986, the vulnerability impacts F5 devices that include F5 iControl REST, a management API interface [PDF] included across multiple F5 products to allow system administrators to change device features and settings remotely. The CVE-2021-22986 vulnerability is what security researchers call an unauthenticated remote command execution vulnerability, meaning an attacker could execute code on an F5 device where the iControl REST API was present without needing to authenticate. This basically means that any F5 iControl REST interface exposed online can be abused, and, hence, the reason why the bug received a 9.8 out of a maximum of 10 on the CVSSv3 vulnerability severity scale. Details about the vulnerability were posted on the F5 website on March 10, and proof-of-concept (PoC) code to exploit the bug was shared on Rapid7's AttackerKB vulnerability assessment portal on Monday, March 15. Uploaded a few of my notes and PoCs from investigating CVE-2021-22986 (F5 iControl REST) this past week. https://t.co/TGCLCR8CzR The PoC, although incomplete, allowed threat actors to craft their custom attack code. Starting March 18, mass-scans have been recorded, with threat actors looking to locate F5 devices with an iControl REST interface exposed online, security firm Bad Packets reported. Today, security firm NCC Group said it saw actual attacks, with threat actors deploying full exploit chains on F5 devices in order to exploit the CVE-2021-22986 vulnerability, if the device hadn't been patched. Hold on to your hats Internet... https://t.co/tJPsevZQia The vulnerability is expected to receive a lot of attention from attackers in the coming months. F5 devices are some of today's most attractive targets to threat actors. They are very popular networking devices used as load balancers and access gateways to control the traffic in and out of large corporate networks, government agencies, data centers, and across ISP infrastructure. When in the summer of 2020, a similar major bug (CVE-2020-5902) was disclosed in F5's BIG-IP load balancer, it came under attack within a day. A week later, it was being exploited by Iranian state-sponsored hackers, and a month later, by China's state hackers, before making its way into the arsenal of ransomware gangs. Something similar is now expected for CVE-2021-22986, a bug just as bad and attacker-friendly as CVE-2020-5902. There is also the issue that this bug was disclosed in the frenzy of the Microsoft Exchange ProxyLogon disclosure and subsequent attacks, which might have led to many companies deprioritizing F5 patching for dealing with the ProxyLogon fixes first. With attacks already happening, system administrators are now urged to focus their efforts on patching CVE-2021-22986 as soon as possible. Because the iControl REST API is included across a wide range of F5 products, it is currently unclear how many devices are vulnerable, but the number is at least 10,000, based on simple BinaryEdge and Shodan searches. To help defenders, the NCC Group team has published today a blog post with detection rules and log artifacts device owners should look to detect attacks against their systems.F5 devices are very popular with attackers
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/threat-actors-start-attacking-f5-devices-using-recent-vulnerability