News: 1615428189

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Now it is F5’s turn to reveal critical security bugs – and the Feds were quick to sound the alarm on these BIG-IP flaws

(2021/03/11)


Security and automation vendor F5 has warned of seven patch-ASAP-grade vulnerabilities in its Big-IP network security and traffic-grooming products, plus another 14 vulns worth fixing.

An [1]advisory dated today lists seven CVEs, four rated critical.

[2]

Most of the bugs concern TMUI – the Traffic Management User Interface that users work with to drive F5 products – and they can be exploited to achieve remote code execution, denial of service attacks, or complete device takeovers; sometimes all three. The iControl REST API that F5 offers to automate its products is also problematic.

To kick off, there's [3]CVE-2021-22987 , which scores a 9.9 on the ten-point CVSS scale of severity as it “allows authenticated users with network access to the Configuration utility, through the BIG-IP management port, or self IP addresses, to execute arbitrary system commands, create or delete files, or disable services.” Administrators are advised the flaw allows “complete system compromise and breakout of Appliance mode.” Note that this can only be exploited via the control plane, and it does require an attacker to have a valid login – so a rogue insider or someone using stolen credentials, perhaps.

[4]

At a mere 9.8 rating, [5]CVE-2021-22986 “allows for unauthenticated attackers with network access to the iControl REST interface, through the BIG-IP management interface and self IP addresses, to execute arbitrary system commands, create or delete files, and disable services.” Complete system compromise is again a possible consequence. We note that this doesn't require authentication, is also only exploitable via the control plane, and yet scores lower than '22987. That's because the latter bug changes the security scope when exploited, apparently.

[6]CVE-2021-22991 and [7]CVE-2021-22992 each score mere 9.0 each.

What do F5, Citrix, Pulse Secure all have in common? China exploiting their flaws to hack govt, biz – Feds [8]READ MORE

If your installation is vulnerable to '22991, “undisclosed requests to a virtual server may be incorrectly handled by Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack." Breaking URL based access control or allowing remote code execution (RCE) are other possible consequences. Google Project Zero's Felix Wilhelm has more technical details [9]here .

The '22992 flaw is also a potential horror show. F5 says: “A malicious HTTP response to an Advanced WAF/ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise.” Google's Wilhelm has a proof-of-concept exploit and more info [10]here .

You’re not out of the woods yet, dear reader, because the next on the list has an 8.8 CVSS rating, so is still very unpleasant. [11]CVE-2021-22988 means that BIG-IP’s Traffic Management User Interface "has an authenticated remote command execution vulnerability in undisclosed pages."

[12]CVE-2021-22989 throttles back the horror with its 8.0 rating, but it allows “highly privileged authenticated users … to execute arbitrary system commands, create or delete files, or disable services.” Complete system compromise and breakout of Appliance mode are again possible.

The runt of the litter, with a 6.6 rating, is [13]CVE-2021-22990 .

Fixes are in if you upgrade BIG-IP to versions 16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3, and 11.6.5.3. CVE-2021-22986 impacts another F5 product, BIG-IQ, and can be fixed with an upgrade to versions 8.0.0, 7.1.0.3, and 7.0.0.2.

F5’s warning about the seven nasties also drops in a mention that it has released details of 14 other CVEs impacting unrelated to those described above. They’re listed [14]here .

European Banking Authority restores email service in wake of Microsoft Exchange hack [15]READ MORE

The seven main bugs are bad enough that America's Cyberspace and Infrastructure Agency (CISA) issued an [16]advisory in which it “encourages users and administrators review the F5 advisory and install updated software as soon as possible.” That's perhaps because foreign miscreants have exploited F5 holes in the past to sneak into networks belonging to Uncle Sam and big business.

CISA and the FBI have also published a [17]Joint Cybersecurity Advisory [PDF] detailing last week’s [18]year-ruining bugs in Microsoft’s Exchange Server.

The dossier says observed attacks exploiting the Exchange flaws are “consistent with previous targeting activity by Chinese cyber actors.”

“Illicitly obtained business information, advanced technology, and research data may undermine business operations and research development of many U.S. companies and institutions,” the document added.

[19]

It identifies “local governments, academic institutions, non-governmental organizations, and business entities in multiple industry sectors, including agriculture, biotechnology, aerospace, defense, legal services, power utilities, and pharmaceutical,” has having been attacked via Microsoft’s mistakes. ®

Get our [20]Tech Resources



[1] https://support.f5.com/csp/article/K02566623

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YEmj6R1MyFglJtrMbd9vnAAAAIM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://support.f5.com/csp/article/K18132488

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YEmj6R1MyFglJtrMbd9vnAAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://support.f5.com/csp/article/K03009991

[6] https://support.f5.com/csp/article/K56715231

[7] https://support.f5.com/csp/article/K52510511

[8] https://www.theregister.com/2020/09/14/chinas_hackers_f5_citrix/

[9] https://bugs.chromium.org/p/project-zero/issues/detail?id=2126

[10] https://bugs.chromium.org/p/project-zero/issues/detail?id=2132

[11] https://support.f5.com/csp/article/K70031188

[12] https://support.f5.com/csp/article/K56142644

[13] https://support.f5.com/csp/article/K45056101

[14] https://support.f5.com/csp/new-updated-articles

[15] https://www.theregister.com/2021/03/09/eba_exchange_breach/

[16] https://us-cert.cisa.gov/ncas/current-activity/2021/03/10/f5-security-advisory-rce-vulnerabilities-big-ip-big-iq

[17] https://www.ic3.gov/Media/News/2021/210310.pdf

[18] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YEmj6R1MyFglJtrMbd9vnAAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[20] https://whitepapers.theregister.com/

Yes... I feel your pain... but as a former first poster (I scored mine a
couple months ago) I know what you went through. Here's where you screwed
up though... YOU DIDN'T PULL THE TRIGGER. You didn't carpe diem.

Yep... When I saw that nice clean article with no posts I didn't hesitate,
yes the adrenaline was surging... my palms were wet, heart pounding. I was
standing at the peak of greatness... I knew I had but one thing to do,
there was no turning back now... I rapidly typed in a one word post.. then
with no hesitation I navigated my mouse over the submit button... and
WHAM.. seconds later I was looking at my feeble post with a #1 attached to
the header. At that mmoment I knew a feeling that only few will ever
know... I was at one with Slashdot... Zen masters and Kings will relate
I'm sure. That one sweet moment when the ying and the yang converge...
bliss... eternal bliss... ahhh!

Then I smoked a cigarette and went to bed.

-- Anonymous Coward, in response to a "First Post!" that clearly wasn't.