Vulnerabilities

Hackers exploit recent F5 BIG-IP flaws in stealthy attacks

0

F5 has warned BIG-IP admins that hackers are exploiting two recently disclosed vulnerabilities that impacts BIG-IP and could result in unauthenticated remote code execution.

F5 BIG-IP is a suite of products and services offering load balancing, security, and performance management for networked applications. The platform is used mainly by large enterprises and government organizations.

Last week, F5 urged admins to apply available security updates for two newly discovered vulnerabilities.

CVE-2023-46747 – Critical (CVSS v3.1 score: 9.8) authentication bypass flaw allowing an attacker to access the Configuration utility and perform arbitrary code execution.

CVE-2023-46748 – High-severity (CVSS v3.1 score: 8.8) SQL injection flaw allowing authenticated attackers with network access to the Configuration utility to execute arbitrary system commands.

Later it was found that the vulnerabilities CVE-2023-46747 and CVE-2023-46748 were being exploited in the wild.

This information is based on the evidence F5 has seen on compromised devices, which appear to be reliable indicators.

All exploited systems may show the same indicators, and it is possible for a skilled attacker to remove traces of their work.

CISA (Cybersecurity & Infrastructure Security Agency) has added the two vulnerabilities to its KEV (Known Exploited Vulnerabilities) catalog, urging federal government agencies to apply the available updates until November 21, 2023.

The impacted and fixed versions include the following:

  • 17.1.0 (affected), fixed on 17.1.0.3 + Hotfix-BIGIP-17.1.0.3.0.75.4-ENG and later
  • 16.1.0 – 16.1.4 (affected), fixed on 16.1.4.1 + Hotfix-BIGIP-16.1.4.1.0.50.5-ENG and later
  • 15.1.0 – 15.1.10 (affected), fixed on 15.1.10.2 + Hotfix-BIGIP-15.1.10.2.0.44.2-ENG and later
  • 14.1.0 – 14.1.5 (affected), fixed on 14.1.5.6 + Hotfix-BIGIP-14.1.5.6.0.10.6-ENG and later
  • 13.1.0 – 13.1.5 (affected), fixed on 13.1.5.1 + Hotfix-BIGIP-13.1.5.1.0.20.2-ENG and later

F5 has released a shell script for versions 14.1.0 and later. The company pointed out that the script must not be used on any BIG-IP version prior to 14.1.0 because it will prevent the Configuration utility from starting.

F5 has observed threat actors using the two flaws in combination, so even applying the mitigation for CVE-2023-46747 could be enough to stop most attacks.

Out of an abundance of caution, admins of exposed BIG-IP devices should proceed straight to the clean-up and restoration phase.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Personal information of 81.5 crore Indians dumped on dark web

Previous article

US sanctions Russian for virtual currency money laundering

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *