¡¾Îó²îͨ¸æ¡¿F5 8Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-08-26

0x00 Îó²î¸ÅÊö

2021Äê8ÔÂ24ÈÕ£¬£¬£¬£¬F5Ðû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËÆäBIG-IPµÈ²úÆ·ÖеÄ29¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î°üÀ¨¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³ÌÏÂÁîÖ´ÐС¢XSS¡¢CSRF¡¢SSRFºÍ¾Ü¾øÐ§À͵ȡ£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

±¾´ÎÐÞ¸´µÄ¸ßΣÎó²îΪ13¸ö£¬£¬£¬£¬³ýCVE-2021-23031Ö®Í⣬£¬£¬£¬ÆäËüÎó²îµÄCVSSÆÀ·Ö¹æÄ£Îª7.2-7.5£¬£¬£¬£¬5¸öÎó²îÓ°ÏìÁË WAF ºÍ ASM£¬£¬£¬£¬1¸öÎó²îÓ°ÏìÁË DNS Ä£¿£¿£¿£¿£¿ £¿ £¿é¡£¡£¡£¡£¡£¡£

ÆäÖаüÀ¨Ò»¸öÔÚÌØ¶¨Ìõ¼þϱ»Ê¹ÓÃʱÆÀ¼¶ÎªÑÏÖØµÄÎó²î£¬£¬£¬£¬¸ÃÎó²îµÄCVE±àºÅΪCVE-2021-23031£¬£¬£¬£¬ÊÇ BIG-IP Web Ó¦Ó÷À»ðǽ (WAF) ºÍÓ¦ÓÃÇå¾²ÖÎÀíÆ÷ (ASM) Á÷Á¿¹ÜÀíÓû§½çÃæ (TMUI) ÉϵÄȨÏÞÌáÉýÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤ÇÒ¾ßÓÐÉèÖÃÊÊÓóÌÐò»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÀ´ÌáÉýȨÏÞ£¬£¬£¬£¬×îÖÕ¿ÉÒÔÖ´ÐÐí§ÒâϵͳÏÂÁî¡¢½¨Éè»òɾ³ýí§ÒâÎļþ¡¢½ûÓÃЧÀ͵ȡ£¡£¡£¡£¡£¡£µ«ÈôÊÇÓ¦ÓÃÁË×°±¸Ä£Ê½£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·Ö½«ÌáÉýΪ9.9¡£¡£¡£¡£¡£¡£

F5±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖеÄ13¸ö¸ßΣÎó²î¼°ÆäÓ°Ïì¹æÄ£¡¢ÐÞ¸´°æ±¾ÈçÏÂ:

CVE ID

ÑÏÖØÐÔ

CVSSÆÀ·Ö

ÊÜÓ°Ïì²úÆ·

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾

CVE-2021-23025

¸ß

7.2

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿ £¿ £¿é£©

15.0.0 - 15.1.0
  14.1.0 - 14.1.3
  13.1.0 - 13.1.3
  12.1.0 - 12.1.6
  11.6.1 - 11.6.5

16.0.0
  15.1.0.5
  14.1.3.1
  13.1.3.5

CVE-2021-23026

¸ß

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿ £¿ £¿é£©

16.0.0 - 16.0.1
  15.1.0 - 15.1.2
  14.1.0 - 14.1.4
  13.1.0 - 13.1.4

12.1.0 - 12.1.6
  11.6.1 - 11.6.5

16.1.0
  16.0.1.2
  15.1.3
  14.1.4.2
  13.1.4.1

BIG-IQ

8.0.0 - 8.1.0 
  7.0.0 - 7.1.0
  6.0.0 - 6.1.0

ÎÞ

CVE-2021-23027

¸ß

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿ £¿ £¿é£©

16.0.0 - 16.0.1
  15.1.0 - 15.1.2
  14.1.0 - 14.1.4

16.1.0
  16.0.1.2
  15.1.3.1
  14.1.4.3

CVE-2021-23028

¸ß

7.5

BIG-IP£¨WAF¡¢ASM£©

16.0.1
  15.1.1 - 15.1.3
  14.1.3.1 - 14.1.4.1
  13.1.3.5 - 13.1.3.6

16.1.0
  16.0.1.2
  15.1.3.1
  14.1.4.2
  13.1.4

CVE-2021-23029

¸ß

7.5

BIG-IP£¨WAF¡¢ASM£©

16.0.0 - 16.0.1

16.1.0
  16.0.1.2

CVE-2021-23030

¸ß

7.5

BIG-IP£¨WAF¡¢ASM£©

16.0.0 - 16.0.1
  15.1.0 - 15.1.3
  14.1.0 - 14.1.4
  13.1.0 - 13.1.4

12.1.0 - 12.1.6

16.1.0
  16.0.1.2
  15.1.3.1
  14.1.4.3
  13.1.4.1

CVE-2021-23031

¸ß/ÑÏÖØ ( ½ö×°±¸Ä£Ê½)

8.8/

9.9 

BIG-IP£¨WAF¡¢ASM£©

16.0.0 - 16.0.1
  15.1.0 - 15.1.2
  14.1.0 - 14.1.4
  13.1.0 - 13.1.3
  12.1.0 - 12.1.5
  11.6.1 - 11.6.5

16.1.0
  16.0.1.2
  15.1.3
  14.1.4.1
  13.1.4
  12.1.6
  11.6.5.3

CVE-2021-23032

¸ß

7.5

BIG-IP (DNS)

16.0.0 - 16.0.1

15.1.0 - 15.1.3

14.1.0 - 14.1.4

13.1.0 - 13.1.4

12.1.0 - 12.1.6

16.1.0 
  15.1.3.1
  14.1.4.4

CVE-2021-23033

¸ß

7.5

BIG-IP£¨WAF¡¢ASM£©

16.0.0 - 16.0.1

15.1.0 - 15.1.3

14.1.0 - 14.1.4

13.1.0 - 13.1.4

12.1.0 - 12.1.6

16.1.0
  15.1.3.1
  14.1.4.3
  13.1.4.1

CVE-2021-23034

¸ß

7.5

BIG-IP

16.0.0 - 16.0.1
  15.1.0 - 15.1.3

16.1.0 
  15.1.3.1

CVE-2021-23035

¸ß

7.5

BIG-IP

14.1.0 - 14.1.4

14.1.4.4

CVE-2021-23036

¸ß

7.5

BIG-IP£¨WAF¡¢ASM¡¢DataSafe£©

16.0.0 - 16.0.1

16.1.0
  16.0.1.2

CVE-2021-23037

¸ß

7.5

BIG-IP

16.0.0 - 16.1.0

15.1.0 - 15.1.3

14.1.0 - 14.1.4

13.1.0 - 13.1.4

12.1.0 - 12.1.6

11.6.1 - 11.6.5

ÎÞ

 

±ðµÄ£¬£¬£¬£¬F5»¹ÐÞ¸´ÁËÆäBIG-IPµÈ²úÆ·ÖÐµÄÆäËü16ÆäÖÐΣºÍµÍΣÎó²î£¬£¬£¬£¬ÕâЩÎó²îµÄCVSSÆÀ·Ö¹æÄ£Îª3.7-6.8£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÖ´ÐÐXSS¹¥»÷¡¢SQL×¢Èë¡¢»á¼ûí§ÒâÎļþµÈ¡£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒÑÔÚ²¿·Ö°æ±¾ÖÐÐÞ¸´£¬£¬£¬£¬F5 ½¨Òé¿Í»§½« BIG-IP ×°±¸ÖÁÉÙ¸üлòÉý¼¶µ½ BIG-IP 14.1.0£¬£¬£¬£¬½« BIG-IP VE ÖÁÉÙ¸üлòÉý¼¶µ½ BIG-IP 15.1.0£¬£¬£¬£¬½¨Òé²Î¿¼¹Ù·½Í¨¸æÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://support.f5.com/csp/article/K50974556

 

0x03 ²Î¿¼Á´½Ó

https://support.f5.com/csp/article/K50974556

https://www.bleepingcomputer.com/news/security/critical-f5-big-ip-bug-impacts-customers-in-sensitive-sectors/

https://securityaffairs.co/wordpress/121454/security/f5-big-ip-critical-flaw.html?

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-26

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png