F5 BIG-IP & BIG-IQ ¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2021-03-110x00 ·ì϶¸ÅÊö
2021Äê03ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬F5°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬¹«¿ªÁËÆäBIG-IPºÍBIG-IQÖеĶà¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬4¸öÑϳÁµÄRCE·ì϶£¬£¬£¬£¬£¬£¬¾¹ýÉí·ÝÑéÖ¤»òδ¾ÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶Զ³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
F5 BIG-IPÊÇÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢ÀûÓ÷¨Ê½°²È«ÖÎÀí¡¢¸ºÔØÆ½ºâµÈÖ°ÄܵÄÀûÓý»¸¶Æ½Ì¨¡£¡£¡£¡£¡£¡£F5 BIG-IQÊÇÒ»Ì×»ùÓÚÈí¼þµÄÔÆÖÎÀí½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬¸Ã¹æ»®Ö§³Ö¿Í»§¿ç¹«¹²ºÍ˽ÓÐÔÆ¡¢´«Í³Êý¾ÝÖÐÐĺͻìºÏ»·¾³²¿ÊðÀûÓý»¸¶ºÍÍøÂç·þÎñ¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

F5 NetworksÊÇÈ«ÇòÆóÒµÍøÂçÉ豸ȷµ±ÏÈÌṩÉÌ£¬£¬£¬£¬£¬£¬ÆäBIG-IP²úÆ·µÄ¿Í»§Ô̺¬µ±¾Ö¡¢¡¶²Æ¸»¡· 500Ç¿¹«Ë¾¡¢ÒøÐÓ×¢»¥ÁªÍø·þÎñÌṩÉÌÒÔ¼°Microsoft¡¢Oracle¡¢FacebookµÈ´óÐÍÆóÒµ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬¡°²Æ¸»50Ç¿ÖÐÓÐ48¼ÒÒÀÀµF5¡±¡£¡£¡£¡£¡£¡£
±¾´ÎF5¹«¿ªµÄ·ì϶ÈçÏ£º
CVE | ÆÀ¼¶ | ÆÀ·Ö | ÊÜÓ°Ïì²úÆ· | ÊÜÓ°Ïì°æ±¾ | ½¨¸´°æ±¾ | É豸ģʽ/·ÇÉ豸ģʽ | ½ÚÔì²ãÃæ/Êý¾Ý²ãÃæ |
CVE-2021-22986 | ÑϳÁ | 9.8 | BIG-IP (All modules) | 16.0.0-16.0.1 | 16.0.1.1 | Both | Control plane ¨C iControl REST |
BIG-IQ | 7.1.0-7.1.0.2 | 8.0.0 | N/A | Control plane ¨C iControl REST | |||
CVE-2021-22987 | ÑϳÁ | 9.9 | BIG-IP (All modules) | 16.0.0-16.0.1 | 16.0.1.1 | Appliance mode | Control plane - TMUI |
CVE-2021-22988 | ¸ß | 8.8 | BIG-IP (All Modules) | 16.0.0-16.0.1 | 16.0.1.1 | Non-Appliance Mode | Control plane - TMUI |
CVE-2021-22989 | ¸ß | 8.0 | BIG-IP Advanced WAF/ASM | 16.0.0-16.0.1 | 16.0.1.1 | Appliance mode | Control plane - TMUI |
CVE-2021-22990 | ÖÐ | 6.6 | BIG-IP Advanced WAF/ASM | 16.0.0-16.0.1 | 16.0.1.1 | Non-Appliance mode | Control plane - TMUI |
CVE-2021-22991 | ÑϳÁ | 9.0 | BIG-IP (All Modules)1 | 16.0.0-16.0.1 | 16.0.1.1 | Both | Data plane |
CVE-2021-22992 | ÑϳÁ | 9.0 | BIG-IP Advanced WAF/ASM | 16.0.0-16.0.1 | 16.0.1.1 | Both | Data plane |
4¸öÑϳÁRCE·ì϶ÏêÇéÈçÏ£º
iControl RESTÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-22986£©
¸Ã·ì϶´æÔÚÓÚiControl RESTÖУ¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Í¨¹ýBIG-IPÖÎÀí½Ó¿ÚºÍ×Ô´øIPµØÖ·Î´ÊÚȨ½Ó¼ûiControl REST½Ó¿Ú£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐËÁÒâϵͳºÅÁî¡¢´´½¨»òɾ³ýÎļþ¡¢½ûÓ÷þÎñµÈ£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂϵͳ±»ÆëÈ«·ÛËé¡£¡£¡£¡£¡£¡£É豸ģʽϵÄBIG-IPÒ²´æÔÚ´Ë·ì϶£¬£¬£¬£¬£¬£¬µ«¸Ã·ì϶ֻÄÜͨ¹ý½ÚÔì²ãÃæÀûÓ㬣¬£¬£¬£¬£¬²»ÄÜͨ¹ýÊý¾Ý²ãÃæÀûÓᣡ£¡£¡£¡£¡£
TMUIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2021-22987£©
ÔÚÉ豸ģʽÏÂÔËÐÐʱ£¬£¬£¬£¬£¬£¬Á÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©£¨Ò²³ÆÎªÅäÖÃʵÓ÷¨Ê½£©ÔÚδ¹«¿ªµÄÒ³ÃæÖдæÔÚ¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌºÅÁîÖ´Ðзì϶£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö9.9¡£¡£¡£¡£¡£¡£¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIPµØÖ·½Ó¼ûTMUI£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐËÁÒâϵͳºÅÁî¡¢´´½¨»òɾ³ýÎļþ¡¢½ûÓ÷þÎñ£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂϵͳÆëÈ«ÊÜËð²¢·ÛËéÉ豸ģʽ£¬£¬£¬£¬£¬£¬´Ë·ì϶ֻÄÜͨ¹ý½ÚÔì²ãÃæÀûÓ㬣¬£¬£¬£¬£¬¶ø²»ÄÜͨ¹ýÊý¾Ý²ãÃæÀûÓᣡ£¡£¡£¡£¡£
TMM»º³åÇøÒç¶Âí½Å£¨CVE-2021-22991£©
Á÷Á¿ÖÎÀí΢Äںˣ¨TMM£©URI¹æ·¶»¯¿ÉÄÜ»áÃýÎ󵨴¦ÖöÔÐé¹¹·þÎñÆ÷µÄδ¹«¿ªÒªÇ󣬣¬£¬£¬£¬£¬Õâ¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂDoS¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚijЩÇé¿öÏ£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÈÆ¹ý»ùÓÚURLµÄ½Ó¼û½ÚÔì»òÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö9.0¡£¡£¡£¡£¡£¡£
Advanced WAF/ASM»º³åÇøÒç¶Âí½Å£¨CVE-2021-22992£©
ÔÚÕ½ÊõÖÐÅäÖÃÁËLogin PageµÄAdvanced WAF/ASMÐé¹¹·þÎñÆ÷ÔÚÏìÓ¦¶ñÒâHTTPʱ¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö9.0¡£¡£¡£¡£¡£¡£
¹¥»÷Õß±ØÐë¿ÉÄܽÚÔìºó¶ËÍøÂç·þÎñÆ÷£¨pool members£©£¬£¬£¬£¬£¬£¬»òÕß¿ÉÄܰѳַþÎñÆ÷¶Ë¶ÔÐé¹¹·þÎñÆ÷µÄHTTPÏìÓ¦£¬£¬£¬£¬£¬£¬ÄÜÁ¦ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄܻᵼÖÂBIG-IP Advanced WAF/ASMϵͳÔâµ½»Ø¾ø·þÎñ£¨DoS£©¹¥»÷£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜÔÚBIG-IP Advanced WAF/ASMϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£´Ë·ì϶ֻÄÜͨ¹ýÊý¾Ý²ãÃæÀûÓ㬣¬£¬£¬£¬£¬¶ø²»ÄÜͨ¹ý½ÚÔì²ãÃæÀûÓᣡ£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
¼øÓÚÕâЩ·ì϶µÄÑϳÁÐÔ£¬£¬£¬£¬£¬£¬½¨Ò龡¿ì×°Öý¨¸´°æ±¾¡£¡£¡£¡£¡£¡£ÒÔÏÂBIG-IP°æ±¾½¨¸´Á˱¾´Î¹«¿ªµÄ7¸ö·ì϶£º
16.0.1.1¡¢15.1.2.1¡¢14.1.4¡¢13.1.3.6¡¢12.1.5.3ºÍ11.6.5.3¡£¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬CVE-2021-22986·ì϶ҲӰÏìBIG-IQ£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚ8.0.0¡¢7.1.0.3ºÍ7.0.0.2Öн¨¸´¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://support.f5.com/csp/article/K02566623
0x03 ²Î¿¼Á´½Ó
https://support.f5.com/csp/article/K02566623
https://support.f5.com/csp/article/K18132488
https://www.bleepingcomputer.com/news/security/f5-urges-customers-to-patch-critical-big-ip-pre-auth-rce-bug/
0x04 ¹¦·òÏß
2021-03-10 F5°ä²¼°²È«²¼¸æ
2021-03-11 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ