CVE-2020-5902 PoC Demo - F5 BIG-IP TMUI RCE Vulnerability

preview_player
Показать описание
This vulnerability allows for unauthenticated attackers, or authenticated users, with network access to the Configuration utility, through the BIG-IP management port and/or self IPs, to view system files and execute arbitrary system commands.

F5 has provided updated software for the several impacted versions of BIG-IP devices.

Several of these vulnerabilities were reported by Mikhail Klyuchnikov of Positive Technologies. TeamARES of Critical Start, Inc. also discovered an issue with the original mitigation.

➨ URLS:
Рекомендации по теме
Комментарии
Автор

Serious vulnerabilities like this one have been popping up lately. What are you doing to address patch management and prevent compromises?

thejonathansinger
Автор

Criticalstart identified this vulnerability

johnrasmussen