One of the world's largest providers of enterprise networking tools, F5 Networks, last week released a patch for a dangerous vulnerabilitythat could harm their systems.

The vulnerability was found in BIG-IP, which consists of appliances that can function as web traffic shaping systems, load balancers, firewalls, access gateways, rate limiters, or SSL middleware.
BIP-IP is one of the most popular networking in use today, as it is used in many government networks around the world, in Internet service provider networks, in cloud computing and in corporate networks in general.
According to F5, its BIG-IP appliances are used in the networks of 48 Fortune 50.
About vulnerability
A researcher at Positive Technologies, named Mikhail Klyuchnikov, was the one who first discovered the vulnerability in BIG-IP, which was named CVE-2020-5902 , and reported it to the company.
This is a vulnerability that allows “remote code execution” and is located in the BIG-IP management interface, known as TMUI.
A hackercould exploit this vulnerability to gain access to the TMUI component, which runs on a Tomcat server on Linux , without the need for valid credentials. A successful exploit could allow attackers to execute arbitrary system commands, create or delete files, disable services and/or execute arbitrary Java , or even gain complete control of a BIG-IP device.

This is an extremely dangerous vulnerability, which received a rare score of 10 out of 10 on the CVSSv3. In practice, this means that it is easy to exploit, automate, use over the Internet, and does not require valid credentials or advanced programming skills for someone to exploit it to their advantage.
Repair is necessary
Due to its severity, the F5 vulnerability needs to be patched immediately, as the devices are primarily used by enterprises and governments and could have a serious impact. Currently, there are approximately 8,400 BIG-IP devices connected to the internet.
