LocateBaltimore
No Result
View All Result
No Result
View All Result
LocateBaltimore
No Result
View All Result
Home Technology

Critical vulnerabilities in BIG-IP appliances leave big networks open to intrusion

Pauline Wright by Pauline Wright
May 8, 2024
in Technology
0
327
SHARES
2.5k
VIEWS
Share on FacebookShare on Twitter


Getty Images

Researchers on Wednesday reported crucial vulnerabilities in a broadly used networking equipment that leaves among the world’s largest networks open to intrusion.

The vulnerabilities reside in BIG-IP Next Central Manager, a element in the newest era of the BIG-IP line of appliances, which organizations use to handle site visitors going into and out of their networks. Seattle-based F5, which sells the product, says its gear is used in 48 of the highest 50 firms as tracked by Fortune. F5 describes the Next Central Manager as a “single, centralized level of management” for managing whole fleets of BIG-IP appliances.

As gadgets performing load balancing, DDoS mitigation, and inspection and encryption of information coming into and exiting giant networks, BIG-IP gear sits at their perimeter and acts as a serious pipeline to among the most security-critical assets housed inside. Those traits have made BIG-IP appliances perfect for hacking. In 2021 and 2022, hackers actively compromised BIG-IP appliances by exploiting vulnerabilities carrying severity scores of 9.8 out of 10.

On Wednesday, researchers from safety agency Eclypsium reported discovering what they mentioned have been 5 vulnerabilities in the newest model of BIG-IP. F5 has confirmed two of the vulnerabilities and launched safety updates that patch them. Eclypsium mentioned three remaining vulnerabilities have gone unacknowledged and it’s unclear if their fixes are included in the newest launch. Whereas the exploited vulnerabilities from 2021 and 2022 affected older BIG-IP variations, the brand new ones reside in the newest model, often called BIG-IP Next. The severity of each vulnerabilities is rated as 7.5.

“BIG-IP Next marks a very new incarnation of the BIG-IP product line touting improved safety, administration, and efficiency,” Eclypsium researchers wrote. “And for this reason these new vulnerabilities are significantly vital—they not solely have an effect on the most recent flagship of F5 code, additionally they have an effect on the Central Manager on the coronary heart of the system.”

Advertisement

The vulnerabilities permit attackers to achieve full administrative management of a tool after which create accounts on programs managed by the Central Manager. “These attacker-controlled accounts wouldn’t be seen from the Next Central Manager itself, enabling ongoing malicious persistence throughout the atmosphere,” Eclypsium mentioned. The researchers mentioned they haven’t any indication any of the vulnerabilities are underneath lively exploitation.

Both of the mounted vulnerabilities could be exploited to extract password hashes or different delicate knowledge that permit for the compromise of administrative accounts on BIG-IP programs. F5 described considered one of them—tracked as CVE-2024-21793—as an Odata injection flaw, a category of vulnerability that permits attackers to inject malicious knowledge into Odata queries. The different vulnerability, CVE-2024-26026, is an SQL injection flaw that may execute malicious SQL statements.

Eclypsium mentioned it reported three extra vulnerabilities. One is an undocumented programming interface that permits for server-side request forgeries, a category of assault that features entry to delicate inner assets which are supposed to be off-limits to outsiders. Another is the flexibility for unauthenticated directors to reset their password even with out realizing what it’s. Attackers who gained management of an administrative account might exploit this final flaw to lock out all authentic entry to a susceptible gadget.

The third is a configuration in the bcrypt password hashing algorithm that makes it attainable to carry out brute-force assaults in opposition to hundreds of thousands of passwords per second. The Open Web Application Security Project says that the bcrypt “work issue”—that means the quantity of assets required to convert plaintext into cryptographic hashes—must be set to a stage no decrease than 10. When Eclypsium carried out its evaluation, the Central Manager set it at six.

Eclypsium researchers wrote:

The vulnerabilities we have now discovered would permit an adversary to harness the facility of Next Central Manager for malicious functions. First, the administration console of the Central Manager could be remotely exploited by any attacker in a position to entry the executive UI through CVE 2024-21793 or CVE 2024-26026. This would consequence in full administrative management of the supervisor itself. Attackers can then make the most of the opposite vulnerabilities to create new accounts on any BIG-IP Next asset managed by the Central Manager. Notably, these new malicious accounts wouldn’t be seen from the Central Manager itself.

All 5 vulnerabilities have been disclosed to F5 in one batch, however F5 solely formally assigned CVEs to the two unauthenticated vulnerabilities. We haven’t confirmed if the opposite 3 have been mounted on the time of publication.

F5 representatives didn’t instantly have a response to the report. Eclypsium went on to say:

Advertisement

These weaknesses can be utilized in a wide range of potential assault paths. At a excessive stage attackers can remotely exploit the UI to achieve administrative management of the Central Manager. Change passwords for accounts on the Central Manager. But most significantly, attackers might create hidden accounts on any downstream gadget managed by the Central Manager.

Eclypsium

The vulnerabilities are current in BIG-IP Next Central Manager variations 20.0.1 by way of 20.1.0. Version 20.2.0, launched Wednesday, fixes the 2 acknowledged vulnerabilities. As famous earlier, it’s unknown if model 20.2.0 fixes the opposite habits Eclypsium described.

“If they’re mounted, it’s +- okay-ish, contemplating the model with them will nonetheless be thought of susceptible to different issues and wish a repair,” Eclypsium researcher Vlad Babkin wrote in an e mail. “If not, the gadget has a long-term method for an authenticated attacker to maintain their entry perpetually, which will likely be problematic.”

A question utilizing the Shodan search engine exhibits solely three cases of susceptible programs being uncovered to the Internet.

Given the latest rash of lively exploits focusing on VPNs, firewalls, load balancers, and different gadgets positioned on the community edge, BIG-IP Central Manager customers would do effectively to place a excessive precedence on patching the vulnerabilities. The availability of proof-of-concept exploitation code in the Eclypsium disclosure additional will increase the chance of lively assaults.



Source hyperlink

Tags: AppliancesbigBIGIPcriticalintrusionleavenetworksopenvulnerabilities
Previous Post

Tell me a story? Baltimore Story Fest coming to Theatre Project

Next Post

JHU creates deadline for protesters to remove their encampments

Next Post
JHU creates deadline for protesters to remove their encampments

JHU creates deadline for protesters to remove their encampments

No Result
View All Result

Categories

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Recent.

How to Make Powdered Sugar (Without Cornstarch Option)

How to Make Powdered Sugar (Without Cornstarch Option)

August 25, 2026
Cream of Asparagus Soup with White Wine

Cream of Asparagus Soup with White Wine

August 25, 2026
Easy Whole Wheat Penne With Broccoli (18-Minute Base)

Easy Whole Wheat Penne With Broccoli (18-Minute Base)

August 24, 2026

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Category

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Tags

2024 Draft 2024 Draft News Air apple Baltimore bridge Chicken Clifton Brown day Derrick Henry draft Easy Experiments Game Gameday Gameday News General Google Heres home Homepage Centerpiece Homepage Latest Headlines iPhone Jackson Key Lamar Lamar Jackson Late For Work Maryland NFL offseason OpenAI Ravens Recipe recipes Ryan Mink Savory season shopping tech TikTok users video Watch week
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.