ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

F5 BIG-IP vulnerabilities leveraged by attackers: What to do?

criticalVulnerability exploited in the wildimportance 60CVE-2023-46747CVE-2023-46748

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-46747
+1 in the same advisory: …46748
F5 BIG-IP TMUI Authentication Bypass Enables Unauthenticated RCE

CVE-2023-46747 is a critical authentication bypass (CVSS 9.8) in the F5 BIG-IP Configuration Utility (TMUI) affecting most BIG-IP modules, including LTM, APM, DNS, AWAF, AFM, ASM, and SSL Orchestrator. By sending undisclosed, specially crafted requests to the TMUI, an attacker with network access to the BIG-IP management port and/or self IP addresses bypasses authentication and can execute arbitrary system commands on the system. No privileges or user interaction are required, and successful exploitation effectively yields full control of the affected BIG-IP deployment. Any organization running vulnerable BIG-IP software is exposed, particularly enterprises, service providers, and government agencies whose management interface or self IPs are reachable. The flaw is being actively exploited: it was added to CISA KEV on 2023-10-31 with known ransomware use, public PoC code exists, and reporting links it to Chinese nation-state actors targeting defense and government networks.

Do: Upgrade all affected BIG-IP systems to the fixed releases identified in F5 advisory K13763 (17.1.0.1, 16.1.4, 15.1.9, 14.1.5.5, or 13.1.5.1 depending on the train, or later); the CISA KEV listing makes remediation mandatory for federal agencies. As an interim mitigation, restrict network access to the TMUI management port and self IP addresses and apply F5's documented mitigation guidance. Given active nation-state and ransomware exploitation, also audit appliances for indicators of compromise such as unexpected accounts, scheduled tasks, and configuration changes.

9.8
group max
97% KEV ransomware PoC ×2
  • f5 BIG-IP Access Policy Manager
  • f5 BIG-IP Advanced Firewall Manager
  • f5 BIG-IP Advanced Web Application Firewall
  • +9 more
largetens of thousands of internet-exposed BIG-IP systems (10k-100k), with a total enterprise installed base plausibly in the hundreds of thousands
Full article360 words · extracted from helpnetsecurity.com · click to collapse

The two BIG-IP vulnerabilities (CVE-2023-46747, CVE-2023-46748) F5 Networks has recently released hotfixes for are being exploited by attackers in the wild, the company has confirmed.

“It is important to note that not all exploited systems may show the same indicators, and, indeed, a skilled attacker may be able to remove traces of their work. It is not possible to prove a device has not been compromised; when there is any uncertainty, you should consider the device compromised,” F5 warned in the updated advisories.

CVE-2023-46747 and CVE-2023-46748 exploited

CVE-2023-46747 is an authentication bypass vulnerability affecting BIG-IP’s Configuration utility (aka Traffic Management User Interface) that may lead to unauthenticated remote code execution. It was reported to F5 in early October by Thomas Hendrickson and Michael Weber of Praetorian Security.

CVE-2023-46748 is an SQL injection vulnerability affecting the same BIG-IP component and may allow an authenticated attacker with network access to it to execute arbitrary system commands. It was reported to F5 by an anonymous researcher.

F5 released hotfixes for the vulnerable devices on October 26. A few days after, Project Discovery released a Nuclei template with the CVE-2023-46747 attack chain and Praetorian released technical details related to the vulnerability and how they exploited it.

Hotfixes, mitigations, and investigation advice

F5 has updated the security advisories for both vulnerabilities on October 30 and has confirmed that the two flaws are being exploited in tandem.

Their advice for admins is still to:

  • Apply the hotfixes as soon as possible
  • Block access to the Configuration utility through self IP addresses or restrict access to trusted users and devices over a secure network

But if these actions haven’t been taken by now, enterprise defenders should work under the assumption that their internet-facing BIG-IP devices have been compromised and should check for indicators of compromise (IoCs) provided by F5.

“This information is based on the evidence F5 has seen on compromised devices, which appear to be reliable indicators,” the company said, but noted that IoCs may vary and that attackers may have been able to remove evidence of their activities.

The Cybersecurity and Infrastructure Agency (CISA) has added CVE-2023-46747 and CVE-2023-46748 to its Known Exploited Vulnerabilities Catalog.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/11/02/cve-2023-46747-cve-2023-46748-exploited/