F5 BIG-IP & BIG-IQ ¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2021-03-11

0x00 ·ì϶¸ÅÊö

2021Äê03ÔÂ10ÈÕ£¬F5°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËÆäBIG-IPºÍBIG-IQÖеĶà¸ö°²È«·ì϶£¬ÆäÖÐÔ̺¬4¸öÑϳÁµÄRCE·ì϶£¬¾­¹ýÉí·ÝÑéÖ¤»òδ¾­ÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶Զ³ÌÖ´ÐдúÂë¡£

F5 BIG-IPÊÇÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢ÀûÓ÷¨Ê½°²È«ÖÎÀí¡¢¸ºÔØÆ½ºâµÈÖ°ÄܵÄÀûÓý»¸¶Æ½Ì¨¡£F5 BIG-IQÊÇÒ»Ì×»ùÓÚÈí¼þµÄÔÆÖÎÀí½â¾ö¹æ»®£¬¸Ã¹æ»®Ö§³Ö¿Í»§¿ç¹«¹²ºÍ˽ÓÐÔÆ¡¢´«Í³Êý¾ÝÖÐÐĺͻìºÏ»·¾³²¿ÊðÀûÓý»¸¶ºÍÍøÂç·þÎñ¡£

 

0x01 ·ì϶ÏêÇé

image.png

F5 NetworksÊÇÈ«ÇòÆóÒµÍøÂçÉ豸ȷµ±ÏÈÌṩÉÌ£¬ÆäBIG-IP²úÆ·µÄ¿Í»§Ô̺¬µ±¾Ö¡¢¡¶²Æ¸»¡· 500Ç¿¹«Ë¾¡¢ÒøÐÓ×¢»¥ÁªÍø·þÎñÌṩÉÌÒÔ¼°Microsoft¡¢Oracle¡¢FacebookµÈ´óÐÍÆóÒµ£¬¸Ã¹«Ë¾°µÊ¾£¬¡°²Æ¸»50Ç¿ÖÐÓÐ48¼ÒÒÀÀµF5¡±¡£

±¾´ÎF5¹«¿ªµÄ·ì϶ÈçÏ£º

CVE

ÆÀ¼¶

ÆÀ·Ö

ÊÜÓ°Ïì²úÆ·

ÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾

É豸ģʽ/·ÇÉ豸ģʽ

½ÚÔì²ãÃæ/Êý¾Ý²ãÃæ

CVE-2021-22986

ÑϳÁ

9.8

BIG-IP   (All modules)

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3

Both

Control   plane ¨C iControl REST


BIG-IQ

7.1.0-7.1.0.2
  7.0.0-7.0.0.1
  6.0.0-6.1.0

8.0.0
  7.1.0.3
  7.0.0.2

N/A

Control   plane ¨C iControl REST

CVE-2021-22987

ÑϳÁ

9.9

BIG-IP   (All modules)

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2
  11.6.1-11.6.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3
  11.6.5.3

Appliance   mode

Control   plane - TMUI

CVE-2021-22988

¸ß

8.8

BIG-IP   (All Modules)

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2
  11.6.1-11.6.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3
  11.6.5.3

Non-Appliance   Mode

Control   plane - TMUI

CVE-2021-22989

¸ß

8.0

BIG-IP   Advanced WAF/ASM

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2
  11.6.1-11.6.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3
  11.6.5.3

Appliance   mode

Control   plane - TMUI

CVE-2021-22990

ÖÐ

6.6

BIG-IP   Advanced WAF/ASM

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2
  11.6.1-11.6.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3
  11.6.5.3

Non-Appliance   mode

Control   plane - TMUI

CVE-2021-22991

ÑϳÁ

9.0

BIG-IP   (All Modules)1

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3

Both

Data   plane

CVE-2021-22992

ÑϳÁ

9.0

BIG-IP   Advanced WAF/ASM

16.0.0-16.0.1
  15.1.0-15.1.2
  14.1.0-14.1.3.1
  13.1.0-13.1.3.5
  12.1.0-12.1.5.2
  11.6.1-11.6.5.2

16.0.1.1
  15.1.2.1
  14.1.4
  13.1.3.6
  12.1.5.3
  11.6.5.3

Both

Data   plane

 

4¸öÑϳÁRCE·ì϶ÏêÇéÈçÏ£º

iControl RESTÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-22986£©

¸Ã·ì϶´æÔÚÓÚiControl RESTÖУ¬ÆäCVSSv3ÆÀ·ÖΪ9.8¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Í¨¹ýBIG-IPÖÎÀí½Ó¿ÚºÍ×Ô´øIPµØÖ·Î´ÊÚȨ½Ó¼ûiControl REST½Ó¿Ú£¬ÒÔÖ´ÐÐËÁÒâϵͳºÅÁî¡¢´´½¨»òɾ³ýÎļþ¡¢½ûÓ÷þÎñµÈ£¬×îÖÕµ¼ÖÂϵͳ±»ÆëÈ«·ÛËé¡£É豸ģʽϵÄBIG-IPÒ²´æÔÚ´Ë·ì϶£¬µ«¸Ã·ì϶ֻÄÜͨ¹ý½ÚÔì²ãÃæÀûÓ㬲»ÄÜͨ¹ýÊý¾Ý²ãÃæÀûÓá£

 

TMUIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2021-22987£©

ÔÚÉ豸ģʽÏÂÔËÐÐʱ£¬Á÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©£¨Ò²³ÆÎªÅäÖÃʵÓ÷¨Ê½£©ÔÚδ¹«¿ªµÄÒ³ÃæÖдæÔÚ¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁîÖ´Ðзì϶£¬ÆäCVSSv3ÆÀ·Ö9.9¡£¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIPµØÖ·½Ó¼ûTMUI£¬ÒÔÖ´ÐÐËÁÒâϵͳºÅÁî¡¢´´½¨»òɾ³ýÎļþ¡¢½ûÓ÷þÎñ£¬×îÖÕµ¼ÖÂϵͳÆëÈ«ÊÜËð²¢·ÛËéÉ豸ģʽ£¬´Ë·ì϶ֻÄÜͨ¹ý½ÚÔì²ãÃæÀûÓ㬶ø²»ÄÜͨ¹ýÊý¾Ý²ãÃæÀûÓá£

 

TMM»º³åÇøÒç¶Âí½Å£¨CVE-2021-22991£©

Á÷Á¿ÖÎÀí΢Äںˣ¨TMM£©URI¹æ·¶»¯¿ÉÄÜ»áÃýÎ󵨴¦ÖöÔÐé¹¹·þÎñÆ÷µÄδ¹«¿ªÒªÇó£¬Õâ¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬´Ó¶øµ¼ÖÂDoS¹¥»÷¡£ÔÚijЩÇé¿öÏ£¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÈÆ¹ý»ùÓÚURLµÄ½Ó¼û½ÚÔì»òÔ¶³ÌÖ´ÐдúÂ룬ÆäCVSSv3ÆÀ·Ö9.0¡£

 

Advanced WAF/ASM»º³åÇøÒç¶Âí½Å£¨CVE-2021-22992£©

ÔÚÕ½ÊõÖÐÅäÖÃÁËLogin PageµÄAdvanced WAF/ASMÐé¹¹·þÎñÆ÷ÔÚÏìÓ¦¶ñÒâHTTPʱ¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬ÆäCVSSv3ÆÀ·Ö9.0¡£

¹¥»÷Õß±ØÐë¿ÉÄܽÚÔìºó¶ËÍøÂç·þÎñÆ÷£¨pool members£©£¬»òÕß¿ÉÄܰѳַþÎñÆ÷¶Ë¶ÔÐé¹¹·þÎñÆ÷µÄHTTPÏìÓ¦£¬ÄÜÁ¦ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄܻᵼÖÂBIG-IP Advanced WAF/ASMϵͳÔâµ½»Ø¾ø·þÎñ£¨DoS£©¹¥»÷£¬ÉõÖÁ¿ÉÄÜÔÚBIG-IP Advanced WAF/ASMϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£´Ë·ì϶ֻÄÜͨ¹ýÊý¾Ý²ãÃæÀûÓ㬶ø²»ÄÜͨ¹ý½ÚÔì²ãÃæÀûÓá£

 

 

0x02 ´ëÖý¨Òé

¼øÓÚÕâЩ·ì϶µÄÑϳÁÐÔ£¬½¨Ò龡¿ì×°Öý¨¸´°æ±¾¡£ÒÔÏÂBIG-IP°æ±¾½¨¸´Á˱¾´Î¹«¿ªµÄ7¸ö·ì϶£º

16.0.1.1¡¢15.1.2.1¡¢14.1.4¡¢13.1.3.6¡¢12.1.5.3ºÍ11.6.5.3¡£

´Ë±í£¬CVE-2021-22986·ì϶ҲӰÏìBIG-IQ£¬¸Ã·ì϶ÒÑÔÚ8.0.0¡¢7.1.0.3ºÍ7.0.0.2Öн¨¸´¡£

ÏÂÔØÁ´½Ó£º

https://support.f5.com/csp/article/K02566623

 

0x03 ²Î¿¼Á´½Ó

https://support.f5.com/csp/article/K02566623

https://support.f5.com/csp/article/K18132488

https://www.bleepingcomputer.com/news/security/f5-urges-customers-to-patch-critical-big-ip-pre-auth-rce-bug/

 

0x04 ¹¦·òÏß

2021-03-10  F5°ä²¼°²È«²¼¸æ

2021-03-11  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png