HomeSecurityF5 fixes two high-severity RCE bugs in its products

F5 fixes two high-severity RCE bugs in its products

F5 has released hotfixes for its BIG-IP and BIG-IQ products, addressing two high-severity flaws that allow attackers to perform unauthorized remote code execution (RCE). The fixes address the issue so users can safely access their data.

See also: Huge wave of TrojanOrders attacks: Magento stores targeted

F5

Although these vulnerabilities are not easy to exploit, they could lead to a full-scale attack on the device.

The first documented flaw, CVE-2022-41622 (CVSS v3 – 8.8), is an unauthorized RCE via cross-site forgery in iControl SOAP, affecting multiple BIG-IP and BIG-IQ versions.

The second flaw is CVE-2022-41800 (CVSS v3 – 8.7), a certified RCE via RPM spec injection, affecting the iControl REST component.

The affected BIG-IP versions are:

  • 13.1.0 – 13.1.5
  • 14.1.0 – 14.1.5
  • 15.1.0 – 15.1.8
  • 16.1.0 – 16.1.3
  • 17.0.0

The affected BIG-IQ versions are:

  • 7.1.0
  • 8.0.0 – 8.2.0

If you are an affected customer, we recommend that you request the technical hotfix for your product version from F5 and install it manually.

As an administrator, you should also disable Basic Authentication for iControl SOAP after installing the hotfix to resolve CVE-2022-41622.

See also: Two Russians charged with operating pirate site Z-Library

F5 fixes two high-severity RCE bugs in its products

Let's look at the technical details that were released

Rapid7 researchers discovered the vulnerabilities in July 2022 and reported them to F5 the following August.

Yesterday, Rapid7 published a detailed report on the flaws that reveals the technical details of the vulnerabilities.

Despite the capabilities of this attack, an administrator would have to actively use the same browser to visit a malicious website as the one used to manage the BIG-IP in order for it to work.

Also, the attacker would need to know the address of the targeted BIG-IP system in order to perform “cross-site request forgery” against the administrator.

Because of this, Rapid7 researcher Ron Bowes believes it is unlikely that the vulnerabilities will be widely exploited.

With CVE-2022-41800, the attacker must have 'Resource Admin' privileges or higher to cause significant damage.

See also: Attacks on US airport websites. The day after

None of the vulnerabilities disclosed by Rapid7 have been known to have been exploited.

Analysts have published extensive technical details, including a proof of concept exploit for CVE-2022-41622. Therefore, it is crucial to address the vulnerabilities as soon as possible.

In addition to the two high-severity flaws, Rapid7 also discovered several security audit bypass methods (SELinux), but these will not be fixed as the vendor did not consider them practically exploitable.

RCE bugs are some of the most dangerous types of security flaws that can exist in software. These vulnerabilities can allow attackers to take complete control of a system remotely and do whatever they want – from installing malware to stealing sensitive data.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS