CVE-2020-5902 | F5 BIG-IPÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-030x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-5902 |
ʱ ¼ä |
2020-07-03 |
|
Àà ÐÍ |
RCE |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
F5 BIG-IP15.1.0¡¢15.0.0¡¢14.1.0-14.1.2¡¢13.1.0-13.1.3¡¢12.1.0-12.1.5¡¢11.6.1-11.6.5 |
0x01 ·ì϶ÏêÇé
F5 BIG-IPÊÇÃÀ¹úF5¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢ÀûÓ÷¨Ê½°²È«ÖÎÀí¡¢¸ºÔØÆ½ºâµÈÖ°ÄܵÄÀûÓý»¸¶Æ½Ì¨¡£BIG-IPÌṩÁËÀûÓ÷¨Ê½¼Ó¿ì¡¢¸ºÔØÆ½ºâ¡¢¿ìÂʵ÷Õû¡¢SSLÐ¶ÔØºÍWebÀûÓ÷¨Ê½·À»¤Ö°ÄÜ¡£¸Ã²úÆ·Òѱ»ºÜ¶à¹«Ë¾Ê¹Óã¬F5Ðû³ÆÈ«Çò50Ç¿¹«Ë¾ÖÐÓÐ48¼ÒÊÇÆä¿Í»§¡£
ÍøÂ簲ȫ¹«Ë¾Positive TechnologiesµÄ×êÑÐÈËÔ±·¢ÏÖÁËBIG-IPÀûÓý»¸¶ÏµÍ³£¨ADC£©µÄÅäÖýӿÚÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-5902£©£¬CVSSÆÀ·Ö10·Ö£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÆëÈ«½ÚÔìÖ¸±êϵͳ¡£
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ò¾¹ýÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýBIG-IPÖÎÀí¶Ë¿Ú»òIP½Ó¼ûTMUI£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâϵͳºÅÁî¡¢´´½¨»òɾ³ýÎļþ¡¢½ûÓ÷þÎñ¡¢Ö´ÐÐËÁÒâµÄJava´úÂë¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§Ḛ́䲼Á˸ÃÈí¼þ11.x°æ±¾£¬12.x°æ±¾£¬13.x°æ±¾£¬14.x°æ±¾ºÍ15.1.0°æ±¾µÄ½¨¸´´ëÊ©£¬15.0.0°æ±¾µÄ½¨¸´´ëÊ©ÔÝδ°ä²¼£¬¾ßÌåÈçÏ£º
һʱ´ëÊ©£º
? All network interfaces
ΪԤ·Àδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓô˷ì϶£¬Ç뽫LocationMatchÅäÖÃÔªËØÔö³¤µ½httpd¡£ÇëÖ´ÐÐÒÔϲ½Ö裺
°ÑÎÈ£º¾¹ýÉí·ÝÑéÖ¤µÄÓû§½«ÒÀÈ»¿ÉÄÜÀûÓô˷ì϶£¬¶øÎÞÐè˼¿¼ÆäÌØÈ¨¼¶±ð¡£
1. ͨ¹ýÊäÈëÒÔϺÅÁîµÇ¼µ½TMOS Shell£¨tmsh£©£º
Tmsh
2. ͨ¹ýÊäÈëÒÔϺÅÁîÀ´±à×ëhttpdÊôÐÔ£º
edit /sys httpd all-properties
3. ÕÒµ½include²¿ÃŲ¢Ôö³¤ÒÔÏÂÄÚÈÝ£º
include '
Redirect 404 /
'
4. ÊäÈëÒÔϺÅÁ±£Áôµ½ÅäÖÃÎļþÖУº
Esc
:wq!
5. ÊäÈëÒÔϺÅÁîÀ´±£ÁôÅäÖãº
save /sys config
6. ÊäÈëÒÔϺÅÁî³ÁÐÂÆô¶¯httpd·þÎñ£º
restart sys service httpd
? Self IPs
ͨ¹ýSelf IPsÕ½Êõ×èÖ¹¶ÔBIG-IPϵͳTMUIµÄ½Ó¼ûȨÏÞ¡£Îª´Ë£¬ÄúÄܹ»½«ÏµÍ³ÖÐÿ¸öSelf IPsµÄPort LockdownÉèÖÃΪ¡°Allow None¡±¡£ÈôÊDZØÐë´ò¿ªËÁÒâ¶Ë¿Ú£¬ÔòӦʹÓÃAllow Custom£¬°ÑÎȲ»ÈݽӼûTMUI¡£Ä¬ÈÏÇé¿öÏ£¬TMUIÕìÌýTCP 443¶Ë¿Ú£¬µ«ÊÇ£¬´ÓBIG-IP 13.0.0°æ±¾ÆðÍ·£¬Single-NIC BIG-IP VE²¿ÊðʹÓÃTCP 8443¶Ë¿Ú£¬Ò²Äܹ»ÅäÖÃ×Ô½ç˵¶Ë¿Ú¡£
°ÑÎÈ£ºÍ¨¹ýSelf IPÕ½Êõ²»ÈݶÔTMUI/Configuration·¨Ê½µÄȨÏ޵ĽӼû£¬Õâ¶ÔÆäËû·þÎñ¿ÉÄܲúÉúÓ°Ïì¡£
ÔÚ¸ü¸ÄSelf IPsµÄÅäÖÃ֮ǰ£¬Çë²Î¿¼ÒÔÏÂÄÚÈÝ£º
https://support.f5.com/csp/article/K17333
https://support.f5.com/csp/article/K13092
https://support.f5.com/csp/article/K31003634
https://support.f5.com/csp/article/K51358480
? Management interface
ÓйØÐÅÏ¢Çë²Î¿¼£º
https://support.f5.com/csp/article/K13309
https://support.f5.com/csp/article/K13092
0x03 ÓйØÐÂÎÅ
https://www.securityweek.com/serious-vulnerabilities-f5s-big-ip-allow-full-system-compromise?from=timeline
0x04 ²Î¿¼Á´½Ó
https://support.f5.com/csp/article/K52145254
0x05 ¹¦·òÏß
2020-07-01 F5°ä²¼°²È«²¼¸æ
2020-07-03 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ