According to an announcement from the US Cybersecurity and Infrastructure Security Agency (CISA) on Friday, the recently patched vulnerability affecting F5 Networks' BIG-IP still poses a risk to organizations.

The vulnerability, which has been designated as CVE-2020-5902 , allows an attacker with access to the product's Traffic Management User Interface (TMUI) utility to obtain credentials and other sensitive data , monitor traffic, and execute arbitrary code or commands, resulting in a complete system compromise.
The issue was uncovered on July 1 by researchers at Positive Technologies, who also estimated that there were thousands of vulnerable devices exposed online, including many in the United States.
A proof-of-concept (PoC) of the vulnerability was released a few days later and the first exploitation attempts were detected on July 5. F5 released a patch for the vulnerability shortly before its disclosure and is now advising its customers to assume that their systems may have been compromised if they failed to successfully install the patch for CVE-2020-5902.
CISA says that government and other agencies have identified suspicious activity related to this flaw since July 6. The agency is investigating several potential breaches resulting from the exploitation of this vulnerability, including against US and commercial organizations, and has so far confirmed two cases where systems have been compromised.
CISA urges organizations to update BIG-IP products as soon as possible and take immediate action if they discover an attack . The company's recommendations in the event of a breach include rebooting compromised hosts, resetting account passwords, restricting access to the vulnerable management interface, and implementing network segmentation to prevent an attacker from moving laterally within the network.
