cbcvebase.
CVE-2020-5902
published 2020-07-01

CVE-2020-5902: In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
100.00%
100.0th percentile
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

Affected

99 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.212.1.5.2
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.413.1.3.4
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.2.614.1.2.6
f5big-ip_access_policy_manager15.0.0 – 15.0.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.0.415.1.0.4
f5big-ip_advanced_firewall_manager>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.212.1.5.2
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.413.1.3.4
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.2.614.1.2.6
f5big-ip_advanced_firewall_manager>= 15.0.0 < 15.0.1.415.0.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.0.415.1.0.4
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.212.1.5.2
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.413.1.3.4
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.2.614.1.2.6
f5big-ip_advanced_web_application_firewall>= 15.0.0 < 15.0.1.415.0.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.0.415.1.0.4
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_analytics>= 12.1.0 < 12.1.5.212.1.5.2

Detection & IOCsextracted from sources · hover to see the quote

urlhxxp[:]//79[.]124[.]8[.]24/bins/
ip78.142.18.20
ip79.124.8.24
hashacb930a41abdc4b055e2e3806aad85068be8d85e0e0610be35e784bfd7cf5b0e
hash037859323285e0bbbc054f43b642c48f2826924149cb1c494cbbf1fc8707f942
hash55c4675a84c1ee40e67209dfde25a5d1c1979454ec2120047026d94f64d57744
hash03254e6240c35f7d787ca5175ffc36818185e62bdfc4d88d5b342451a747156d
hash204cbad52dde24ab3df41c58021d8039910bf7ea07645e70780c2dbd66f7e90b
hash3f8e65988b8e2909f0ea5605f655348efb87565566808c29d136001239b7dfa9
hash15b2ee07246684f93b996b41578ff32332f4f2a60ef3626df9dc740405e45751
hash0ca27c002e3f905dddf9083c9b2f8b3c0ba8fb0976c6a06180f623c6acc6d8ca
hashecc1e3f8332de94d830ed97cd07867b90a405bc9cc1b8deccec51badb4a2707c
hashe71aca778ea1753973b23e6aa29d1445f93dc15e531c706b6165502d6cf0bfa4
urlhttps://github.com/rapid7/metasploit-framework/blob/0417e88ff24bf05b8874c953bd91600f10186ba4/modules/exploits/linux/http/f5_bigip_tmui_rce.rb
snort
54462
  • The fetch.sh dropper uses iptables to drop packets on Telnet, SSH, and HTTP default ports on infected devices, and creates cron jobs for persistence. Look for unexpected iptables rules blocking management ports and new cron entries executing a binary named 'sysctl' from a non-standard path.
  • CVE-2020-5902 exploitation involves directory traversal in the TMUI (Traffic Management User Interface). Detect path traversal sequences such as '..;/' in HTTP requests to BIG-IP TMUI endpoints.
  • Use Snort rule 54462 (released by Cisco Talos) to detect exploitation attempts against CVE-2020-5902 in BIG-IP TMUI.
  • ·The vulnerability is particularly dangerous for BIG-IP instances whose web interface is exposed to the internet and indexed on search engines such as Shodan. Over 1000 publicly-available vulnerable devices were observed on Shodan at time of disclosure.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.