Article Details
Scrape Timestamp (UTC): 2023-11-01 04:57:25.680
Source: https://thehackernews.com/2023/11/alert-f5-warns-of-active-attacks.html
Original Article Text
Click to Toggle View
Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability. F5 is warning of active abuse of a critical security flaw in BIG-IP less than a week after its public disclosure that could result in the execution of arbitrary system commands as part of an exploit chain. Tracked as CVE-2023-46747 (CVSS score: 9.8), the vulnerability allows an unauthenticated attacker with network access to the BIG-IP system through the management port to achieve code execution. A proof-of-concept (PoC) exploit has since been made available by ProjectDiscovery. It impacts the following versions of the software - Now the company is alerting that it has "observed threat actors using this vulnerability to exploit CVE-2023-46748," which refers to an authenticated SQL injection vulnerability in the BIG-IP Configuration utility. "This vulnerability may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands," F5 noted in an advisory for CVE-2023-46748 (CVSS score: 8.8). In other words, bad actors are chaining the two flaws to run arbitrary system commands. To check for indicators of compromise (IoCs) associated with the SQL injection flaw, users are recommended to check the /var/log/tomcat/catalina.out file for suspicious entries like below 0 The Shadowserver Foundation, in a post on X (formerly Twitter), said it has been "seeing F5 BIG-IP CVE-2023-46747 attempts in our honeypot sensors" since October 30, 2023, making it imperative that users move quickly to apply the fixes.
Daily Brief Summary
F5 has issued an alert regarding active exploitation of a critical security flaw in BIG-IP, tracked as CVE-2023-46747 with a CVSS score of 9.8.
The vulnerability enables unauthenticated attackers with network access to the BIG-IP system to execute arbitrary system commands.
The issue impacts all versions of the software and a proof-of-concept exploit has been released by ProjectDiscovery.
F5 also reported threat actors exploiting CVE-2023-46748, an authenticated SQL injection vulnerability in BIG-IP configuration utility with a CVSS score of 8.8.
Cyber attackers are using the two vulnerabilities in combination to execute arbitrary system commands.
F5 advises users looking for indications of compromise to check designated log files for suspicious entries.
The Shadowserver Foundation reported detecting attempts to exploit F5 BIG-IP CVE-2023-46747 since October 30, 2023, urging users to quickly apply the necessary fixes.