Cyber Command backs 'urgent' patch for F5 security vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5902 | Unauthenticated RCE via path traversal in F5 BIG-IP TMUI CVE-2020-5902 is a critical, unauthenticated remote code execution flaw in the F5 BIG-IP Traffic Management User Interface (TMUI), the appliance's web management console, rooted in a directory/path traversal issue (CWE-22) in undisclosed TMUI pages. It is triggered by sending crafted HTTP(S) requests to the management interface — classically path-traversal URLs beneath the TMUI application on the management port — which lets an attacker bypass authentication, read or delete arbitrary files, and execute commands without credentials. Successful exploitation yields full control of the BIG-IP system, which attackers can use to pivot into networks the appliance fronts, maintain persistence, and deploy ransomware. Any organization running an affected F5 BIG-IP appliance or virtual edition whose TMUI is reachable, or whose management network can be reached, is exposed; F5's installed base spans large enterprises and service providers, so the footprint is broad. Exploitation is confirmed in the wild: the flaw was mass-scanned and exploited within days of its July 2020 disclosure, it is listed in CISA KEV with known ransomware use, and EPSS assigns a ~100% probability of exploitation within 30 days. Do: Patch immediately using F5's advisory K52145254 — upgrade BIG-IP to a fixed release per the vendor's version matrix, since CISA's required action is applying vendor updates. Until patched, restrict TMUI/management-interface access to trusted source IPs or a VPN (or disable TMUI if unused) and apply F5's published interim workaround. Because ransomware use is confirmed, hunt for indicators of compromise on both patched and unpatched appliances (unexpected files, webshells, modified login pages, new accounts or scheduled tasks) before treating systems as clean. | 9.8 | 100% | KEV ransomware PoC ×8 |
| mass≈100,000–300,000 internet-exposed BIG-IP TMUI endpoints, with a far larger internal installed base |
Full article748 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
One of the largest providers of enterprise networking equipment in the world, F5, issued a patch for an issue that, if exploited, could lead to “complete system compromise.”
One of the largest providers of enterprise networking equipment in the world, F5 Networks, has issued a security fix for a major vulnerability that, if exploited, could result in a “complete system compromise.”
F5’s BIG-IP is among the most popular networking gear in use today in government systems, internet service providers and cloud computing data centers. If security administrators fail to patch the new vulnerability, though, attackers could wreak havoc on their networks, according to a information security specialists. Mikhail Klyuchnikov, the senior web application security researcher at Positive Technologies who uncovered the flaw, estimates that there are approximately 8,000 vulnerable devices exposed to the internet.
The remote code execution vulnerability, designated CVE-2020-5902, affects the BIG-IP product’s Traffic Management User Interface (TMUI), which can enable load balancers, firewalls, rate limiters and web traffic shaping systems. Attackers who exploit the weakness can execute arbitrary system commands, create files, delete files or disable services, according to F5.
The vulnerability is so serious it received the highest possible score of 10 from the Common Vulnerability Scoring System (CVSS). The Department of Defense’s Cyber Command warned in a tweet Friday that patching is “URGENT,” and that it “should not be postponed over the weekend.” The Department of Homeland Security’s cybersecurity agency also advised administrators to update their F5 systems on July 4.
“If you didn’t patch by this morning, assume [you are] compromised,” the Cybersecurity and Infrastructure Security Agency (CISA) Director Chris Krebs said in a tweet Monday. “Keep patching and check logs.”
To exploit the flaw, an attacker would need to send a specially crafted HTTP request to servers hosting the BIG-IP TMUI, according to Klyuchnikov.
Remote code execution by attackers “in this case results from security flaws in multiple components, such as one that allows directory traversal exploitation,” Klyuchnikov said in a statement. “This is particularly dangerous for companies whose F5 BIG-IP web interface is listed on search engines such as Shodan.”
Rich Warren, principal security consultant at NCC Group, said his company had observed active exploitation soon after the government started pushing out its alerts.
“So far, attacks have been varied and opportunistic, and we’ve seen a sharp rise following the public release of tooling to make it trivial for low-skilled hackers to exploit,” Warren told CyberScoop. “We are continually monitoring and flagging any new and novel attempts to exploit this vulnerability, and we’d encourage all [organizations] to update themselves and act now if they think they have been compromised.”
By press time Monday, NCC Group had observed an increase in exploitation attempts via the public Metasploit module. While many of the first exploits emanated from Italy, a “large volume” of attempts at “identifying vulnerable servers, which the attacker can then come back to and exploit further later,” has been emanating from China, Warren told CyberScoop.
It’s the second flaw revealed last week that received a CVSS score of 10. Cyber Command also highlighted a critical flaw in Palo Alto Networks technology that also received the highest score.
Vulnerable versions of BIG-IP include 11.6.x, 12.1.x, 13.1.x, 14.1.x, 15.0.x, 15.1.x, according to Positive Technologies.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cyber-command-f5-security-flaw/