securityaffairs · @securityaffairs
385 followers · 291 posts · Server infosec.exchange
securityaffairs · @securityaffairs
385 followers · 291 posts · Server infosec.exchange

A High-severity bug in BIG-IP can lead to code execution and DoS
securityaffairs.com/141728/sec

#f5 #securityaffairs #hacking #BIGIP

Last updated 2 years ago

Redhotcyber · @redhotcyber
171 followers · 104 posts · Server mastodon.bida.im

F5 risolve due pericolose RCE che possono portare alla compromissione di BIG-IP e BIG-IQ

Gli sviluppatori di hanno rilasciato per i prodotti e . Le hanno risolto due gravi che potevano consentire agli aggressori non autenticati di eseguire in remoto codice arbitrario () su vulnerabili.

Fortunatamente, lo sfruttamento di entrambi i problemi richiede il rispetto di determinate condizioni, il che rende difficile sfruttare queste . Tuttavia, F5 avverte che uno sfruttamento riuscito può portare alla completa dei dispositivi.

lnkd.in/dgRMZV5C

#infosecurity #privacy #CyberSecurityNews #cybersecuritytraining #CyberSecurityAwareness #cybercrime #cybersecurity #hacking #dataprotection #ethicalhacking #informationsecurity #redhotcyber #compromissione #endpoint #rce #vulnerabilità #patch #BIGIQ #BIGIP #correzioni #f5

Last updated 2 years ago

Graham Gold :donor: · @cirriustech
1151 followers · 2783 posts · Server infosec.exchange
Ron Bowes · @iagox86
861 followers · 123 posts · Server infosec.exchange

Wrote up a pair of entries for the two vulnerabilities in that we released today (largely the same as the blog, but more focus on technical and less on the story):

attackerkb.com/topics/i21EbdNx

attackerkb.com/topics/ZClTQn4a

#attackerkb #f5 #BIGIP

Last updated 2 years ago

Shoe · @cybershoe
4 followers · 5 posts · Server hachyderm.io

A couple of CVEs dropped today outside of our normal notification cadence.

TL;DR: If you haven't left your or management interfaces open to the world, you're probably in pretty good shape, but still go and read the notification; there are additional mitigation steps in the CVE articles: support.f5.com/csp/article/K97

Also check out the video @aubreykingf5 posted from DevCentral with some more details about the vulns, impact, and mitigation: youtu.be/qRoc0sXlHUg

#f5 #BIGIP #BIGIQ #infosec

Last updated 2 years ago

Ron Bowes · @iagox86
861 followers · 123 posts · Server infosec.exchange

I'm excited to share of my work that came out today! Specifically, a handful of vulnerabilities in devices that I worked on through the summer, and worked with the vendor to get patched (F5 was awesome to work with, btw!).

I wrote a super detailed #blog post, and also wrote a full PoC. modules (both for the exploits and some post-exploitation data-gathering) are incoming as well!

The most important of the issues is via a vulnerability in the interface (), which is pretty cool (though requires a confluence of conditions to actually matter). I also had to bypass to actually exploit this on the path I chose, which is kinda cool.

The other is authenticated RCE, to which they assigned , though even I, the person who found it, doesn't really think it's a big deal. It's a nice way to get a session on your test box, at least?

I also published a bunch of my #tools for analyzing F5, including scripts to build, parse, and requests to their proprietary (I think?) database protocol (these require a valid login to use, but there's no user separation so there's a bit of ).

I'll also be speaking about this research in much more detail (as much as I can in 45 minutes :) ) in my talk on Dec 2!

#f5 #BIGIP #blog #metasploit #rce #csrf #soap #cve_2022_41622 #selinux #cve_2022_41800 #meterpreter #tools #mitm #LPE #Hushcon

Last updated 2 years ago

· @OkiePapist
88 followers · 1741 posts · Server noagendasocial.com

For all my dudes named Ben out there:

*****WARNING*****

If you are upgrading your and staying on version 12, the version you need is 12.1.5.3 has a memory leak and you NEED an engineering hot fix from F5.

lnkd.in/dE9UESg

#BIGIP #f5 #netops #devops #secops #cloud #adc

Last updated 4 years ago