- Product
Product Overview
Sophisticated security with unmatched simplicityCloud SIEM
Pre-configured detections across your environmentHoneypots
Deception technology to detect lateral movementEndpoint Visibility
Real-time monitoring with added detection & responseSecurity Reports
Data visualizations, compliance reports, and executive summariesAutomated Response
Detect, prioritize, and neutralize threats around the clockIntegrations
Cloud, on-prem, and open API connectionsXDR Platform
A complete view to identify risk, and things operational
- Pricing
- Why Blumira
Why Blumira
The Security Operations platform IT teams loveWatch A Demo
See Blumira in action and how it builds operational resilienceUse Cases
A unified security solution for every challengePricing
Unlimited data and predictable pricing structureCompany
Our human-centered approach to cybersecurityCompare Blumira
Find out how Blumira stacks up to similar security toolsIntegrations
Cloud, on-prem, and open API connectionsCustomer Stories
Learn how others like you found success with Blumira
- Solutions
- Partners
- Resources
A private security researcher named Mikhail Klyuchnikov disclosed a substantial vulnerability relating to F5 Networks’ product BIG-IP over the weekend. F5 BIG-IP LTM uses specialized hardware to offload SSL encryption from data center servers. F5 BIG-IP LTM works to improve application performance.
Known as CVE-2020-5902, this vulnerability was given a 10 out of 10 severity, which is a rare occurrence in the CVEs we see today. The reason for this score is due to the impact this exploit can have remotely and unauthenticated (potentially resulting in complete system compromise), as well as the simplicity of this attack.
How It Works
This vulnerability affects the Traffic Management User Interface (TMUI), also referred to as the Configuration utility. It can allow for remote code execution, and doesn’t require any authentication.
Exploitation is simple. When attackers find a F5 BIG-IP on the internet, they simply have to run a login string command in the address bar to gain access to a victim’s system. These strings can be found here on GitHub.
Researcher Mikhail Klyuchnikov said:
By exploiting this vulnerability, a remote attacker with access to the BIG-IP configuration utility could, without authorization, perform remote code execution (RCE1). The attacker can create or delete files, disable services, intercept information, run arbitrary system commands and Java code, completely compromise the system, and pursue further targets, such as the internal network.
RCE, in this case, results from security flaws in multiple components, such as one that allows directory traversal exploitation. This is particularly dangerous for companies whose F5 BIG-IP web interface is listed on search engines such as Shodan. Fortunately, most companies using the product do not enable access to the interface from the internet.
Who’s Affected & Mitigation
As stated above, only companies that enable public internet access to their F5 BIG-IP web interface are affected.
Affected companies are advised to update. Vulnerable versions of BIG-IP (11.6.x, 12.1.x, 13.1.x, 14.1.x, 15.0.x, 15.1.x) should be replaced by the corresponding updated versions (11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4).
Users of public cloud marketplaces such as AWS, Azure, GCP, and Alibaba should switch to BIG-IP Virtual Edition (VE) versions 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.0.1.4, or 15.1.0.4, if available.
F5 has released a fix in their latest patch release, found in Solution K52145254.
Nick Dixon
Nick is a cybersecurity professional with over a decade of experience in IT security and operations management. A Detroit native and graduate of Eastern Michigan University's Information Assurance program, he currently serves as Security Analysts & Technical Support Manager at Blumira, where he has advanced through...
More from the blog
View All Posts
Security How-To
7 min read
| June 10, 2020
How to Mitigate Against the SMBleed Vulnerability & POC Exploit
Read More
Security Alerts
5 min read
| December 9, 2021
Critical Bugs Discovered In SonicWall SMA 100 Series Appliances
Read More
Security Alerts
10 min read
| June 30, 2021
PrintNightmare (CVE-2021-1675 and CVE 2021-34527) Explained
Read MoreSubscribe to email updates
Stay up-to-date on what's happening at this blog and get additional content about the benefits of subscribing.