F5 BIG-IP & BIG-IQ ¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-03-110x00 Îó²î¸ÅÊö
2021Äê03ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬F5Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬¹ûÕæÁËÆäBIG-IPºÍBIG-IQÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨4¸öÑÏÖØµÄRCEÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤»òδÂÄÀúÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
F5 BIG-IPÊÇÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢Ó¦ÓóÌÐòÇå¾²ÖÎÀí¡¢¸ºÔØÆ½ºâµÈ¹¦Ð§µÄÓ¦Óý»¸¶Æ½Ì¨¡£¡£¡£¡£¡£¡£F5 BIG-IQÊÇÒ»Ì×»ùÓÚÈí¼þµÄÔÆÖÎÃ÷È·¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¼Æ»®Ö§³Ö¿Í»§¿ç¹«¹²ºÍ˽ÓÐÔÆ¡¢¹Å°åÊý¾ÝÖÐÐĺͻìÏýÇéÐΰ²ÅÅÓ¦Óý»¸¶ºÍÍøÂçЧÀÍ¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

F5 NetworksÊÇÈ«ÇòÆóÒµÍøÂç×°±¸µÄÁìÏÈÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬£¬ÆäBIG-IP²úÆ·µÄ¿Í»§°üÀ¨Õþ¸®¡¢¡¶²Æ²ú¡· 500Ç¿¹«Ë¾¡¢ÒøÐС¢»¥ÁªÍøÐ§ÀÍÌṩÉÌÒÔ¼°Microsoft¡¢Oracle¡¢FacebookµÈ´óÐÍÆóÒµ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¡°²Æ²ú50Ç¿ÖÐÓÐ48¼ÒÒÀÀµF5¡±¡£¡£¡£¡£¡£¡£
±¾´ÎF5¹ûÕæµÄÎó²îÈçÏ£º
CVE | ÆÀ¼¶ | ÆÀ·Ö | ÊÜÓ°Ïì²úÆ· | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | ×°±¸Ä£Ê½/·Ç×°±¸Ä£Ê½ | ¿ØÖƲãÃæ/Êý¾Ý²ãÃæ |
CVE-2021-22986 | ÑÏÖØ | 9.8 | BIG-IP (All modules) | 16.0.0-16.0.1 | 16.0.1.1 | Both | Control plane ¨C iControl REST |
BIG-IQ | 7.1.0-7.1.0.2 | 8.0.0 | N/A | Control plane ¨C iControl REST | |||
CVE-2021-22987 | ÑÏÖØ | 9.9 | BIG-IP (All modules) | 16.0.0-16.0.1 | 16.0.1.1 | Appliance mode | Control plane - TMUI |
CVE-2021-22988 | ¸ß | 8.8 | BIG-IP (All Modules) | 16.0.0-16.0.1 | 16.0.1.1 | Non-Appliance Mode | Control plane - TMUI |
CVE-2021-22989 | ¸ß | 8.0 | BIG-IP Advanced WAF/ASM | 16.0.0-16.0.1 | 16.0.1.1 | Appliance mode | Control plane - TMUI |
CVE-2021-22990 | ÖÐ | 6.6 | BIG-IP Advanced WAF/ASM | 16.0.0-16.0.1 | 16.0.1.1 | Non-Appliance mode | Control plane - TMUI |
CVE-2021-22991 | ÑÏÖØ | 9.0 | BIG-IP (All Modules)1 | 16.0.0-16.0.1 | 16.0.1.1 | Both | Data plane |
CVE-2021-22992 | ÑÏÖØ | 9.0 | BIG-IP Advanced WAF/ASM | 16.0.0-16.0.1 | 16.0.1.1 | Both | Data plane |
4¸öÑÏÖØRCEÎó²îÏêÇéÈçÏ£º
iControl RESTÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-22986£©
¸ÃÎó²î±£´æÓÚiControl RESTÖУ¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔͨ¹ýBIG-IPÖÎÀí½Ó¿ÚºÍ×Ô´øIPµØµãδÊÚȨ»á¼ûiControl REST½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐí§ÒâϵͳÏÂÁî¡¢½¨Éè»òɾ³ýÎļþ¡¢½ûÓÃЧÀ͵ȣ¬£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂϵͳ±»ÍêÈ«ÆÆË𡣡£¡£¡£¡£¡£×°±¸Ä£Ê½ÏµÄBIG-IPÒ²±£´æ´ËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÎó²îÖ»ÄÜͨ¹ý¿ØÖƲãÃæÊ¹Ó㬣¬£¬£¬£¬£¬£¬£¬²»¿Éͨ¹ýÊý¾Ý²ãÃæÊ¹Óᣡ£¡£¡£¡£¡£
TMUIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22987£©
ÔÚ×°±¸Ä£Ê½ÏÂÔËÐÐʱ£¬£¬£¬£¬£¬£¬£¬£¬Á÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©£¨Ò²³ÆÎªÉèÖÃÊÊÓóÌÐò£©ÔÚδ¹ûÕæµÄÒ³ÃæÖб£´æ¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö9.9¡£¡£¡£¡£¡£¡£¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIPµØµã»á¼ûTMUI£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐí§ÒâϵͳÏÂÁî¡¢½¨Éè»òɾ³ýÎļþ¡¢½ûÓÃЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂϵͳÍêÈ«ÊÜËð²¢ÆÆËð×°±¸Ä£Ê½£¬£¬£¬£¬£¬£¬£¬£¬´ËÎó²îÖ»ÄÜͨ¹ý¿ØÖƲãÃæÊ¹Ó㬣¬£¬£¬£¬£¬£¬£¬¶ø²»¿Éͨ¹ýÊý¾Ý²ãÃæÊ¹Óᣡ£¡£¡£¡£¡£
TMM»º³åÇøÒç³öÎó²î£¨CVE-2021-22991£©
Á÷Á¿ÖÎÀí΢Äںˣ¨TMM£©URI¹æ·¶»¯¿ÉÄÜ»á¹ýʧµØ´¦Öóͷ£¶ÔÐéÄâЧÀÍÆ÷µÄδ¹ûÕæÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂDoS¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßÈÆ¹ý»ùÓÚURLµÄ»á¼û¿ØÖÆ»òÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö9.0¡£¡£¡£¡£¡£¡£
Advanced WAF/ASM»º³åÇøÒç³öÎó²î£¨CVE-2021-22992£©
ÔÚÕ½ÂÔÖÐÉèÖÃÁËLogin PageµÄAdvanced WAF/ASMÐéÄâЧÀÍÆ÷ÔÚÏìÓ¦¶ñÒâHTTPʱ¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö9.0¡£¡£¡£¡£¡£¡£
¹¥»÷Õß±ØÐèÄܹ»¿ØÖƺó¶ËÍøÂçЧÀÍÆ÷£¨pool members£©£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÄܹ»Ê¹ÓÃЧÀÍÆ÷¶Ë¶ÔÐéÄâЧÀÍÆ÷µÄHTTPÏìÓ¦£¬£¬£¬£¬£¬£¬£¬£¬²Å»ªÊ¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄܻᵼÖÂBIG-IP Advanced WAF/ASMϵͳÔâµ½¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜÔÚBIG-IP Advanced WAF/ASMϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£´ËÎó²îÖ»ÄÜͨ¹ýÊý¾Ý²ãÃæÊ¹Ó㬣¬£¬£¬£¬£¬£¬£¬¶ø²»¿Éͨ¹ý¿ØÖƲãÃæÊ¹Óᣡ£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¼øÓÚÕâЩÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬£¬£¬½¨Ò龡¿ì×°ÖÃÐÞ¸´°æ±¾¡£¡£¡£¡£¡£¡£ÒÔÏÂBIG-IP°æ±¾ÐÞ¸´Á˱¾´Î¹ûÕæµÄ7¸öÎó²î£º
16.0.1.1¡¢15.1.2.1¡¢14.1.4¡¢13.1.3.6¡¢12.1.5.3ºÍ11.6.5.3¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬CVE-2021-22986Îó²îÒ²Ó°ÏìBIG-IQ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚ8.0.0¡¢7.1.0.3ºÍ7.0.0.2ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://support.f5.com/csp/article/K02566623
0x03 ²Î¿¼Á´½Ó
https://support.f5.com/csp/article/K02566623
https://support.f5.com/csp/article/K18132488
https://www.bleepingcomputer.com/news/security/f5-urges-customers-to-patch-critical-big-ip-pre-auth-rce-bug/
0x04 ʱ¼äÏß
2021-03-10 F5Ðû²¼Ç徲ͨ¸æ
2021-03-11 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ