CVE-2020-5902 | F5 BIG-IPÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-07-03

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-5902

ʱ    ¼ä

2020-07-03

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

F5 BIG-IP15.1.0¡¢15.0.0¡¢14.1.0-14.1.2¡¢13.1.0-13.1.3¡¢12.1.0-12.1.5¡¢11.6.1-11.6.5


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



F5 BIG-IPÊÇÃÀ¹úF5¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢ÀûÓ÷¨Ê½°²È«ÖÎÀí¡¢¸ºÔØÆ½ºâµÈÖ°ÄܵÄÀûÓý»¸¶Æ½Ì¨¡£¡£¡£¡£ ¡£BIG-IPÌṩÁËÀûÓ÷¨Ê½¼Ó¿ì¡¢¸ºÔØÆ½ºâ¡¢Ëٶȵ÷Õû¡¢SSLÐ¶ÔØºÍWebÀûÓ÷¨Ê½·À»¤Ö°ÄÜ¡£¡£¡£¡£ ¡£¸Ã²úÆ·Òѱ»ºÜ¶à¹«Ë¾Ê¹Ó㬣¬£¬£¬£¬ £¬£¬£¬F5Ðû³ÆÈ«Çò50Ç¿¹«Ë¾ÖÐÓÐ48¼ÒÊÇÆä¿Í»§¡£¡£¡£¡£ ¡£

ÍøÂ簲ȫ¹«Ë¾Positive TechnologiesµÄ×êÑÐÈËÔ±·¢ÏÖÁËBIG-IPÀûÓý»¸¶ÏµÍ³£¨ADC£©µÄÅäÖýӿÚÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-5902£©£¬£¬£¬£¬£¬ £¬£¬£¬CVSSÆÀ·Ö10·Ö£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÆëÈ«½ÚÔìÖ¸±êϵͳ¡£¡£¡£¡£ ¡£

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ò¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýBIG-IPÖÎÀí¶Ë¿Ú»òIP½Ó¼ûTMUI£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâϵͳºÅÁî¡¢´´½¨»òɾ³ýÎļþ¡¢½ûÓ÷þÎñ¡¢Ö´ÐÐËÁÒâµÄJava´úÂë¡£¡£¡£¡£ ¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§Ḛ́䲼Á˸ÃÈí¼þ11.x°æ±¾£¬£¬£¬£¬£¬ £¬£¬£¬12.x°æ±¾£¬£¬£¬£¬£¬ £¬£¬£¬13.x°æ±¾£¬£¬£¬£¬£¬ £¬£¬£¬14.x°æ±¾ºÍ15.1.0°æ±¾µÄ½¨¸´´ëÊ©£¬£¬£¬£¬£¬ £¬£¬£¬15.0.0°æ±¾µÄ½¨¸´´ëÊ©ÔÝδ°ä²¼£¬£¬£¬£¬£¬ £¬£¬£¬¾ßÌåÈçÏ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



һʱ´ëÊ©£º

? All network interfaces

ΪԤ·Àδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓô˷ì϶£¬£¬£¬£¬£¬ £¬£¬£¬Ç뽫LocationMatchÅäÖÃÔªËØÔö³¤µ½httpd¡£¡£¡£¡£ ¡£ÇëÖ´ÐÐÒÔϲ½Ö裺

°ÑÎÈ£º¾­¹ýÉí·ÝÑéÖ¤µÄÓû§½«ÒÀÈ»¿ÉÄÜÀûÓô˷ì϶£¬£¬£¬£¬£¬ £¬£¬£¬¶øÎÞÐè˼¿¼ÆäÌØÈ¨¼¶±ð¡£¡£¡£¡£ ¡£

1. ͨ¹ýÊäÈëÒÔϺÅÁîµÇ¼µ½TMOS Shell£¨tmsh£©£º

Tmsh

2. ͨ¹ýÊäÈëÒÔϺÅÁîÀ´±à×ëhttpdÊôÐÔ£º

edit /sys httpd all-properties

3. ÕÒµ½include²¿ÃŲ¢Ôö³¤ÒÔÏÂÄÚÈÝ£º

include '

Redirect 404 /


'

4. ÊäÈëÒÔϺÅÁ£¬£¬£¬£¬ £¬£¬£¬±£Áôµ½ÅäÖÃÎļþÖУº

Esc

:wq!

5. ÊäÈëÒÔϺÅÁîÀ´±£ÁôÅäÖãº

save /sys config

6. ÊäÈëÒÔϺÅÁî³ÁÐÂÆô¶¯httpd·þÎñ£º

restart sys service httpd

? Self IPs

ͨ¹ýSelf IPsÕ½Êõ×èÖ¹¶ÔBIG-IPϵͳTMUIµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£ ¡£Îª´Ë£¬£¬£¬£¬£¬ £¬£¬£¬ÄúÄܹ»½«ÏµÍ³ÖÐÿ¸öSelf IPsµÄPort LockdownÉèÖÃΪ¡°Allow None¡±¡£¡£¡£¡£ ¡£ÈôÊDZØÐë´ò¿ªËÁÒâ¶Ë¿Ú£¬£¬£¬£¬£¬ £¬£¬£¬ÔòӦʹÓÃAllow Custom£¬£¬£¬£¬£¬ £¬£¬£¬°ÑÎȲ»ÈݽӼûTMUI¡£¡£¡£¡£ ¡£Ä¬ÈÏÇé¿öÏ£¬£¬£¬£¬£¬ £¬£¬£¬TMUIÕìÌýTCP 443¶Ë¿Ú£¬£¬£¬£¬£¬ £¬£¬£¬µ«ÊÇ£¬£¬£¬£¬£¬ £¬£¬£¬´ÓBIG-IP 13.0.0°æ±¾ÆðÍ·£¬£¬£¬£¬£¬ £¬£¬£¬Single-NIC BIG-IP VE²¿ÊðʹÓÃTCP 8443¶Ë¿Ú£¬£¬£¬£¬£¬ £¬£¬£¬Ò²Äܹ»ÅäÖÃ×Ô½ç˵¶Ë¿Ú¡£¡£¡£¡£ ¡£

°ÑÎÈ£ºÍ¨¹ýSelf IPÕ½Êõ²»ÈݶÔTMUI/Configuration·¨Ê½µÄȨÏ޵ĽӼû£¬£¬£¬£¬£¬ £¬£¬£¬Õâ¶ÔÆäËû·þÎñ¿ÉÄܲúÉúÓ°Ïì¡£¡£¡£¡£ ¡£

ÔÚ¸ü¸ÄSelf IPsµÄÅäÖÃ֮ǰ£¬£¬£¬£¬£¬ £¬£¬£¬Çë²Î¿¼ÒÔÏÂÄÚÈÝ£º

https://support.f5.com/csp/article/K17333

https://support.f5.com/csp/article/K13092

https://support.f5.com/csp/article/K31003634

https://support.f5.com/csp/article/K51358480

? Management interface

ÓйØÐÅÏ¢Çë²Î¿¼£º

https://support.f5.com/csp/article/K13309

https://support.f5.com/csp/article/K13092


0x03 ÓйØÐÂÎÅ


https://www.securityweek.com/serious-vulnerabilities-f5s-big-ip-allow-full-system-compromise?from=timeline


0x04 ²Î¿¼Á´½Ó


https://support.f5.com/csp/article/K52145254


0x05 ¹¦·òÏß


2020-07-01 F5°ä²¼°²È«²¼¸æ

2020-07-03 VSRC°ä²¼·ì϶¹«¸æ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website