Rewterz
Rewterz Threat Alert – Donot APT group Targeting Pakistan
March 10, 2021
Rewterz
Rewterz Threat Advisory – CVE-2020-13959 – Apache Velocity Tools cross-site scripting
March 11, 2021

Rewterz Threat Advisory – Multiple F5 BIG-IP Security Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-22992

F5 BIG-IP is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the is_hdr_criteria_matches function. By sending a specially crafted HTTP response, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service.

CVE-2021-22991

F5 BIG-IP is vulnerable to a buffer overflow, caused by improper bounds checking by Traffic Management Microkernel (TMM) URI normalization. By sending undisclosed requests, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

CVE-2021-22990, CVE-2021-22989, CVE-2021-22988, CVE-2021-22987

F5 BIG-IP could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by an error in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility. An attacker could exploit this vulnerability using the control plane to execute arbitrary system commands, create or delete files, and disable services.

CVE-2021-22986

F5 BIG-IP could allow a remote attacker to execute arbitrary commands on the system, caused by an error in the iControl REST interface. An attacker could exploit this vulnerability using the control plane to execute arbitrary system commands, create or delete files, and disable services.

Impact

  • Denial of service
  • Command execution
  • Arbitrary code execution

Affected Vendors

F5

Affected Products

  • F5 BIG-IP (ASM) 14.1.0
  • F5 BIG-IQ 6.0.0
  • F5 BIG-IQ 6.1.0
  • F5 BIG-IP (ASM) 15.0.0

Remediation

Refer to F5 Security Advisory for complete list of affected products, patches.

F5 Security Advisory K02566623