¡¾Îó²îͨ¸æ¡¿F5 BIG-IP/BIG-IQ ¶à¸ö¸ßΣÎó²îͨ¸æ
2021-03-11
Ò». Îó²î¸ÅÊö
3ÔÂ11ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½F5¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËÓ°ÏìF5µÄBIG-IPºÍBIG-IQµÄ¶à¸ö¸ßΣÎó²î£¨CVE-2021-22986£¬CVE-2021-22987£¬CVE-2021-22988£¬CVE-2021-22989£¬CVE-2021-22990£¬CVE-2021-22991£¬CVE-2021-22992£©£¬½¨ÒéÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
BIG-IP ÊÇÃÀ¹ú F5 ¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢Ó¦ÓóÌÐòÇå¾²ÖÎÀí¡¢¸ºÔØÆ½ºâµÈ¹¦Ð§µÄÓ¦Óý»¸¶Æ½Ì¨¡£BIG-IQ ÊÇÒ»¿îÓÃÓÚÖÎÀíºÍе÷ F5 Çå¾²ÓëÓ¦Óý»¸¶½â¾ö¼Æ»®µÄÖÇÄÜ¿ò¼Ü¡£
²Î¿¼Á´½Ó£º
https://support.f5.com/csp/article/K02566623
¶þ. ÖØµãÎó²îÐÎò
iControl RESTÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22986£©£º
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÿØÖƽçÃæ¾ÙÐÐʹÓã¬Í¨¹ýBIG-IPÖÎÀí½çÃæ»ò×ÔÉíIPµØµã¶ÔiControl REST½Ó¿Ú¾ÙÐÐÍøÂç»á¼û£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁ½¨Éè»òɾ³ýÎļþÒÔ¼°½ûÓ÷þÎñ£¬×°±¸Ä£Ê½ÏµÄBIG-IPϵͳҲÈÝÒ×Êܵ½¹¥»÷¡£CVSSÆÀ·ÖΪ9.8¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K03009991
Á÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22987£©£º
µ±ÒÔ×°±¸Ä£Ê½ÔËÐÐʱ£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÿØÖƽçÃæ¾ÙÐÐʹÓã¬Í¨¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIP»á¼ûTMUI£¬¿ÉÄܵ¼ÖÂϵͳÍêÈ«ÊÜËð²¢ÆÆËð×°±¸Ä£Ê½£¬CVSSÆÀ·ÖΪ9.9¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K18132488
TMUIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22988£©£º
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÿØÖƽçÃæÊ¹ÓôËÎó²î£¬Í¨¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIP»á¼ûTMUI£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁ½¨Éè»òɾ³ýÎļþ»ò½ûÓ÷þÎñ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K70031188
×°±¸Ä£Ê½Advanced WAF/ASM TMUI Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22989£©£º
µ±ÔÚ×°±¸Ä£Ê½ÏÂÉèÖÃÁËAdvanced WAF»òASMʱ£¬¾ßÓÐÖÎÀíÔ±£¬×ÊÔ´ÖÎÀíÔ±»òÓ¦ÓóÌÐòÇå¾²ÖÎÀíÔ±½ÇÉ«Éí·ÝµÄ¹¥»÷Õßͨ¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíµØµã»á¼ûTMUI£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁ½¨Éè»òɾ³ýÎļþ£¬»ò½ûÓ÷þÎñ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K56142644
Advanced WAF/ASM TMUI Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22990£©£º
ÔÚÅ䱸ÁËAdvanced WAF»òBIG-IP ASMµÄϵͳÉÏ£¬¾ßÓÐÖÎÀíÔ±£¬×ÊÔ´ÖÎÀíÔ±»òÓ¦ÓóÌÐòÇå¾²ÖÎÀíÔ±½ÇÉ«Éí·ÝµÄ¹¥»÷Õßͨ¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIPµØµã»á¼ûTMUI£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁ½¨Éè»òɾ³ýÎļþ£¬»ò½ûÓ÷þÎñ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K45056101
TMM»º³åÇøÒç³öÎó²î£¨CVE-2021-22991£©£º
Á÷Á¿ÖÎÀí΢Äںˣ¨TMM£©URI¹æ·¶»¯¿ÉÄÜ»á¹ýʧµØ´¦Öóͷ£¶ÔÐéÄâ·þÎñÆ÷µÄÇëÇ󣬴Ӷø´¥·¢»º³åÇøÒç³ö£¬µ¼ÖÂDoS¹¥»÷¡£¹¥»÷Õßͨ¹ýÊý¾Ý²ãÃæ¾ÙÐÐʹÓã¬ÔÚijЩÇéÐÎÏ£¬¿ÉÄÜÈÆ¹ý»ùÓÚURLµÄ»á¼û¿ØÖÆ»òʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬CVSSÆÀ·ÖΪ9.0¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K56715231
Advanced WAF/ASM»º³åÇøÒç³öÎó²î£¨CVE-2021-22992£©£º
¶ÔÕ½ÂÔÖÐÉèÖÃÁË“µÇÂ¼Ò³Ãæ”µÄAdvanced WAF / BIG-IP ASMÐéÄâ·þÎñÆ÷µÄ¶ñÒâHTTPÏìÓ¦¿ÉÄܻᴥ·¢»º³åÇøÒç³ö£¬´Ó¶øµ¼ÖÂDoS¹¥»÷¡£¹¥»÷Õßͨ¹ýÊý¾Ý²ãÃæ¾ÙÐÐʹÓã¬ÔÚijЩÇéÐÎÏ£¬¿ÉÄÜÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£CVSSÆÀ·ÖΪ9.0¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://support.f5.com/csp/article/K52510511
Èý. Ó°Ïì¹æÄ£
CVE-2021-22986£º
ÊÜÓ°Ïì°æ±¾
BIG-IP£º16.0.0-16.0.1
BIG-IP£º15.1.0-15.1.2
BIG-IP£º14.1.0-14.1.3.1
BIG-IP£º13.1.0-13.1.3.5
BIG-IP£º12.1.0-12.1.5.2
BIG-IQ£º7.1.0-7.1.0.2
BIG-IQ£º7.0.0-7.0.0.1
BIG-IQ£º6.0.0-6.1.0
²»ÊÜÓ°Ïì°æ±¾
BIG-IP£º16.0.1.1
BIG-IP£º15.1.2.1
BIG-IP£º14.1.4
BIG-IP£º13.1.3.6
BIG-IP£º12.1.5.3
BIG-IQ£º8.0.0
BIG-IQ£º7.1.0.3
BIG-IQ£º7.0.0.2
CVE-2021-22987/CVE-2021-22988/CVE-2021-22989/CVE-2021-22990/CVE-2021-22992£º
ÊÜÓ°Ïì°æ±¾
BIG-IP£º16.0.0-16.0.1
BIG-IP£º15.1.0-15.1.2
BIG-IP£º14.1.0-14.1.3.1
BIG-IP£º13.1.0-13.1.3.5
BIG-IP£º12.1.0-12.1.5.2
BIG-IP£º11.6.1-11.6.5.2
²»ÊÜÓ°Ïì°æ±¾
BIG-IP£º16.0.1.1
BIG-IP£º15.1.2.1
BIG-IP£º14.1.4
BIG-IP£º13.1.3.6
BIG-IP£º12.1.5.3
BIG-IP£º11.6.5.3
CVE-2021-22991£º
ÊÜÓ°Ïì°æ±¾
BIG-IP£º16.0.0-16.0.1
BIG-IP£º15.1.0-15.1.2
BIG-IP£º14.1.0-14.1.3.1
BIG-IP£º13.1.0-13.1.3.5
BIG-IP£º12.1.0-12.1.5.2
²»ÊÜÓ°Ïì°æ±¾
BIG-IP£º16.0.1.1
BIG-IP£º15.1.2.1
BIG-IP£º14.1.4
BIG-IP£º13.1.3.6
BIG-IP£º12.1.5.3
ËÄ. Îó²î¼ì²â
4.1 °æ±¾¼ì²â
Ò»¡¢Óû§¿Éͨ¹ýÔÚTMOS shell£¨tmsh£©ÖÐÊäÈëÒÔÏÂÏÂÁÉó²éÄ¿½ñʹÓõİ汾£º
|
show sys version |

¶þ¡¢Óû§Ò²¿ÉµÇ¼WebÖÎÀí½çÃæÉó²éÄ¿½ñBIG-IPµÄ°æ±¾£º
Èô°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ¼´±£´æÇ徲Σº¦¡£

Îå. Îó²î·À»¤
5.1 ¹Ù·½Éý¼¶
ÏÖÔÚF5¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´ÁËÒÔÉÏÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁ¶ÔÓ¦°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
BIG-IP£ºhttps://support.f5.com/csp/article/K9502
BIG-IQ£ºhttps://support.f5.com/csp/article/K15113
Éý¼¶Ö¸ÄÏÓë×¢ÖØÊÂÏîÇë²ÎÔÄ:
BIG-IP£ºhttps://support.f5.com/csp/article/K13123
BIG-IQ£ºhttps://support.f5.com/csp/article/K15106
5.2 ÔÝʱ·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶²Ù×÷£¬¿É½ÓÄÉÒÔϲ½·¥¾ÙÐлº½â¡£
CVE-2021-22986£º
եȡͨ¹ý×ÔÉíIPµØµã»á¼ûiControl REST£º½«ÏµÍ³ÖÐÿ¸öIPµØµãµÄPort LockdownÑ¡ÏîÉèÖÃΪAllow None¡£ ÈôÊDZØÐ迪·Åij¶Ë¿Ú£¬Ôò¿ªÆôAllow CustomÑ¡Ïî¡£ ĬÈÏÇéÐÎÏ£¬iControl REST¼àÌý443¶Ë¿Ú¡£
եȡͨ¹ýÖÎÀí½çÃæ»á¼ûiControl REST£º½ö½«ÖÎÆÊÎö¼ûȨÏÞ¿ª·Å¸øÊÜÐÅÍеÄÓû§ºÍF5×°±¸¡£
CVE-2021-22987/CVE-2021-22988/CVE-2021-22989/ CVE-2021-22989£º
եȡͨ¹ý×ÔÉíIPµØµã»á¼ûÉèÖÃÊÊÓóÌÐò£º½«ÏµÍ³ÉÏÿ¸öIPµØµãµÄPort LockdownÑ¡ÏîÉèÖøü¸ÄΪAllow None¡£ ÈôÊDZØÐ迪·Åij¶Ë¿Ú£¬Ôò¿ªÆôAllow CustomÑ¡ÏĬÈÏÇéÐÎÏ£¬ÉèÖÃÊÊÓóÌÐò¼àÌý443¶Ë¿Ú¡£
եȡͨ¹ýÖÎÀí½çÃæ»á¼ûÉèÖÃÊÊÓóÌÐò£º½ö½«ÖÎÆÊÎö¼ûȨÏÞ¿ª·Å¸øÊÜÐÅÍеÄÓû§ºÍF5×°±¸¡£
CVE-2021-22992£º
ʹÓÃiRule»º½â¶ñÒâÅþÁ¬£º
1. µÇ¼ÉèÖÃÊÊÓóÌÐò
2. ½øÈëLocal Traffic > iRules > iRule List
3. Ñ¡ÔñCreate
4. ÊäÈëiRuleµÄÃû³Æ
5. ÔÚDefinitionÖÐÌí¼ÓÒÔÏÂiRule´úÂ룺
The server response is invalid. Please inform the administrator. Error: K52510511
|
# Mitigation for K52510511: Advanced WAF/ASM Buffer Overflow vulnerability CVE-2021-22992 when RULE_INIT { # Set static::debug 1 to enable debug logging. set static::debug 0 set static::max_length 4000 } when HTTP_REQUEST { if {$static::debug}{ set LogString "Client [IP::client_addr]:[TCP::client_port] -> [HTTP::host][HTTP::uri]" } set uri [string tolower [HTTP::uri]] } when HTTP_RESPONSE { set header_names [HTTP::header names] set combined_header_name [join $header_names ""] set combined_header_name_len [string length $combined_header_name] if {$static::debug}{ log local0. "=================response======================" log local0. "$LogString (response)" log local0. "combined header names: $combined_header_name" foreach aHeader [HTTP::header names] { log local0. "$aHeader: [HTTP::header value $aHeader]" } log local0. "the length of the combined response header names: $combined_header_name_len" log local0. "=============================================" } if { ( $combined_header_name_len > $static::max_length ) } { log local0. "In the response of '$uri', the length of the combined header names $combined_header_name_len exceeds the maximum value $static::max_length. See K52510511: Advanced WAF/ASM Buffer Overflow vulnerability CVE-2021-22992" HTTP::respond 502 content " |
"
} } |
6. Ñ¡ÔñFinished
7. ½«iRuleÓëÊÜÓ°ÏìµÄÐéÄâ·þÎñÆ÷Ïà¹ØÁª
Ð޸ĵǼ½çÃæÉèÖãº
1. µÇ¼µ½ÊÜÓ°ÏìµÄAdvanced WAF/ASMϵͳµÄÉèÖÃÊÊÓóÌÐò
2. ½øÈëSecurity > Application Security > Sessions and Logins > Login Pages List
3. ´ÓCurrent edited policy listÖÐÑ¡ÔñÇå¾²Õ½ÂÔ
4. ´ÓÕâÁ½¸öÉèÖÃÖÐɾ³ýËùÓÐÉèÖÃ
5. Ñ¡ÔñÉúÑÄÒÔÉúÑĸü¸Ä
6. Ñ¡ÔñApply Policy£¬Ó¦Óøü¸Ä
7. Ñ¡ÔñOKÒÔÈ·ÈϲÙ×÷
ɾ³ýÉϰ¶Ò³Ã棺
1. µÇ¼µ½ÊÜÓ°ÏìµÄBIG-IP Advanced WAF/ASMϵͳµÄÉèÖÃÊÊÓóÌÐò
2. ½øÈëSecurity > Application Security > Sessions and Logins > Login Pages List
3. ´ÓCurrent edited policy listÖÐÑ¡ÔñÇå¾²Õ½ÂÔ
4. ѡժҪɾ³ýµÄµÇÂ¼Ò³ÃæÉèÖÃ
5. Ñ¡ÔñDelete
6. Ñ¡ÔñOKÈ·ÈÑþ³Øý
7. Ñ¡ÔñApply Policy£¬Ó¦Óøü¸Ä
8. Ñ¡ÔñOKÈ·ÈϲÙ×÷
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







