¡¾Îó²îͨ¸æ¡¿F5 8Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-08-260x00 Îó²î¸ÅÊö
2021Äê8ÔÂ24ÈÕ£¬£¬£¬£¬F5Ðû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËÆäBIG-IPµÈ²úÆ·ÖеÄ29¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î°üÀ¨¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³ÌÏÂÁîÖ´ÐС¢XSS¡¢CSRF¡¢SSRFºÍ¾Ü¾øÐ§À͵ȡ£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐÞ¸´µÄ¸ßΣÎó²îΪ13¸ö£¬£¬£¬£¬³ýCVE-2021-23031Ö®Í⣬£¬£¬£¬ÆäËüÎó²îµÄCVSSÆÀ·Ö¹æÄ£Îª7.2-7.5£¬£¬£¬£¬5¸öÎó²îÓ°ÏìÁË WAF ºÍ ASM£¬£¬£¬£¬1¸öÎó²îÓ°ÏìÁË DNS Ä£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£
ÆäÖаüÀ¨Ò»¸öÔÚÌØ¶¨Ìõ¼þϱ»Ê¹ÓÃʱÆÀ¼¶ÎªÑÏÖØµÄÎó²î£¬£¬£¬£¬¸ÃÎó²îµÄCVE±àºÅΪCVE-2021-23031£¬£¬£¬£¬ÊÇ BIG-IP Web Ó¦Ó÷À»ðǽ (WAF) ºÍÓ¦ÓÃÇå¾²ÖÎÀíÆ÷ (ASM) Á÷Á¿¹ÜÀíÓû§½çÃæ (TMUI) ÉϵÄȨÏÞÌáÉýÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤ÇÒ¾ßÓÐÉèÖÃÊÊÓóÌÐò»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÀ´ÌáÉýȨÏÞ£¬£¬£¬£¬×îÖÕ¿ÉÒÔÖ´ÐÐí§ÒâϵͳÏÂÁî¡¢½¨Éè»òɾ³ýí§ÒâÎļþ¡¢½ûÓÃЧÀ͵ȡ£¡£¡£¡£¡£¡£µ«ÈôÊÇÓ¦ÓÃÁË×°±¸Ä£Ê½£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·Ö½«ÌáÉýΪ9.9¡£¡£¡£¡£¡£¡£
F5±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖеÄ13¸ö¸ßΣÎó²î¼°ÆäÓ°Ïì¹æÄ£¡¢ÐÞ¸´°æ±¾ÈçÏÂ:
CVE ID | ÑÏÖØÐÔ | CVSSÆÀ·Ö | ÊÜÓ°Ïì²úÆ· | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ |
CVE-2021-23025 | ¸ß | 7.2 | BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£© | 15.0.0 - 15.1.0 | 16.0.0 |
CVE-2021-23026 | ¸ß | 7.5 | BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£© | 16.0.0 - 16.0.1 12.1.0 - 12.1.6 | 16.1.0 |
BIG-IQ | 8.0.0 - 8.1.0 | ÎÞ | |||
CVE-2021-23027 | ¸ß | 7.5 | BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£© | 16.0.0 - 16.0.1 | 16.1.0 |
CVE-2021-23028 | ¸ß | 7.5 | BIG-IP£¨WAF¡¢ASM£© | 16.0.1 | 16.1.0 |
CVE-2021-23029 | ¸ß | 7.5 | BIG-IP£¨WAF¡¢ASM£© | 16.0.0 - 16.0.1 | 16.1.0 |
CVE-2021-23030 | ¸ß | 7.5 | BIG-IP£¨WAF¡¢ASM£© | 16.0.0 - 16.0.1 12.1.0 - 12.1.6 | 16.1.0 |
CVE-2021-23031 | ¸ß/ÑÏÖØ ( ½ö×°±¸Ä£Ê½) | 8.8/ 9.9 | BIG-IP£¨WAF¡¢ASM£© | 16.0.0 - 16.0.1 | 16.1.0 |
CVE-2021-23032 | ¸ß | 7.5 | BIG-IP (DNS) | 16.0.0 - 16.0.1 15.1.0 - 15.1.3 14.1.0 - 14.1.4 13.1.0 - 13.1.4 12.1.0 - 12.1.6 | 16.1.0 |
CVE-2021-23033 | ¸ß | 7.5 | BIG-IP£¨WAF¡¢ASM£© | 16.0.0 - 16.0.1 15.1.0 - 15.1.3 14.1.0 - 14.1.4 13.1.0 - 13.1.4 12.1.0 - 12.1.6 | 16.1.0 |
CVE-2021-23034 | ¸ß | 7.5 | BIG-IP | 16.0.0 - 16.0.1 | 16.1.0 |
CVE-2021-23035 | ¸ß | 7.5 | BIG-IP | 14.1.0 - 14.1.4 | 14.1.4.4 |
CVE-2021-23036 | ¸ß | 7.5 | BIG-IP£¨WAF¡¢ASM¡¢DataSafe£© | 16.0.0 - 16.0.1 | 16.1.0 |
CVE-2021-23037 | ¸ß | 7.5 | BIG-IP | 16.0.0 - 16.1.0 15.1.0 - 15.1.3 14.1.0 - 14.1.4 13.1.0 - 13.1.4 12.1.0 - 12.1.6 11.6.1 - 11.6.5 | ÎÞ |
±ðµÄ£¬£¬£¬£¬F5»¹ÐÞ¸´ÁËÆäBIG-IPµÈ²úÆ·ÖÐµÄÆäËü16ÆäÖÐΣºÍµÍΣÎó²î£¬£¬£¬£¬ÕâЩÎó²îµÄCVSSÆÀ·Ö¹æÄ£Îª3.7-6.8£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÖ´ÐÐXSS¹¥»÷¡¢SQL×¢Èë¡¢»á¼ûí§ÒâÎļþµÈ¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒÑÔÚ²¿·Ö°æ±¾ÖÐÐÞ¸´£¬£¬£¬£¬F5 ½¨Òé¿Í»§½« BIG-IP ×°±¸ÖÁÉÙ¸üлòÉý¼¶µ½ BIG-IP 14.1.0£¬£¬£¬£¬½« BIG-IP VE ÖÁÉÙ¸üлòÉý¼¶µ½ BIG-IP 15.1.0£¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½Í¨¸æÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://support.f5.com/csp/article/K50974556
0x03 ²Î¿¼Á´½Ó
https://support.f5.com/csp/article/K50974556
https://www.bleepingcomputer.com/news/security/critical-f5-big-ip-bug-impacts-customers-in-sensitive-sectors/
https://securityaffairs.co/wordpress/121454/security/f5-big-ip-critical-flaw.html?
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-08-26 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º