EXECUTIVE SUMMARY
Recent research has uncovered remotely exploitable vulnerabilities within F5’s Next Central Manager, granting attackers full administrative control and the ability to clandestinely create accounts on managed assets. These vulnerabilities pose significant threats to network infrastructure, especially as they affect F5’s latest flagship products, including the Central Manager, pivotal to system operations. Exploitation of the Central Manager’s management console, facilitated by CVE-2024-21793 or CVE-2024-26026, results in complete administrative control over the manager. Subsequently, attackers can leverage other vulnerabilities to create new accounts on managed BIG-IP Next assets, concealed from the Central Manager. While these vulnerabilities were collectively reported to F5, only CVEs were assigned to the two unauthenticated vulnerabilities.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Recent research has uncovered remotely exploitable vulnerabilities within F5’s Next Central Manager, granting attackers full administrative control and the ability to clandestinely create accounts on managed assets. These vulnerabilities pose significant threats to network infrastructure, especially as they affect F5’s latest flagship products, including the Central Manager, pivotal to system operations. Exploitation of the Central Manager’s management console, facilitated by CVE-2024-21793 or CVE-2024-26026, results in complete administrative control over the manager. Subsequently, attackers can leverage other vulnerabilities to create new accounts on managed BIG-IP Next assets, concealed from the Central Manager. While these vulnerabilities were collectively reported to F5, only CVEs were assigned to the two unauthenticated vulnerabilities.[emaillocker id="1283"]
Additionally, an undocumented API vulnerability permits SSRF of URL paths, enabling attackers to call any API method on any managed device. This allows for the creation of onboard accounts on devices, invisible to the Central Manager, facilitating persistent access even after system patches and password resets. Inadequate bcrypt cost of 6 and admin password self-reset without previous password knowledge are further identified vulnerabilities, compromising system security. These weaknesses open avenues for various attack paths, including remote exploitation of the UI, administrative control acquisition, password changes, and hidden account creation on downstream devices managed by the Central Manager.
Given the heightened risk posed by such vulnerabilities in network infrastructure management systems, organizations must maintain vigilance and enforce stringent access controls. Implementing a policy enforcement mechanism separate from the management interface, such as zero-trust principles, can bolster security measures effectively. Organizations may also consider augmenting their defense mechanisms with solutions, offering integrity checking, detection of malicious behavior, and other capabilities to safeguard IT infrastructure, including network devices.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/new-big-ip-next-central-manager-bugs-allow-device-takeover/
https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/