¡¾Îó²îͨ¸æ¡¿F5 8Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-08-05

0x00 Îó²î¸ÅÊö

2022Äê8ÔÂ3ÈÕ£¬ £¬£¬£¬£¬£¬F5Ðû²¼Ç徲ͨ¸æ£¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä¶à¸ö²úÆ·ÖеĶà¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢Çå¾²ÈÆ¹ý¡¢È¨ÏÞÌáÉýºÍ¾Ü¾øÐ§À͵ȡ£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

F5±¾´Î¹²ÐÞ¸´ÁË22¸öÎó²î£¬ £¬£¬£¬£¬£¬ÆäÖÐÓÐ12¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬ £¬£¬£¬£¬£¬8¸öÎó²îÆÀ¼¶ÎªÖÐΣ£¬ £¬£¬£¬£¬£¬1¸öÎó²îÆÀ¼¶ÎªµÍΣ£¬ £¬£¬£¬£¬£¬ÏêÇéÈçÏ£º

CVE-ID

Ãû³Æ

ÆÀ·Ö

ÊÜÓ°Ïì²úÆ·

Ó°Ïì¹æÄ£

ÐÞ¸´°æ±¾

CVE-2022-35243

F5 BIG-IP   iControl REST

Çå¾²ÈÆ¹ýÎó²î£¨½ö×°±¸Ä£Ê½Ï£¬ £¬£¬£¬£¬£¬ÇÒÐèÉí·ÝÑéÖ¤£©

8.7

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.2

15.1.0 - 15.1.5

14.1.0 - 14.1.4

13.1.0 - 13.1.5

17.0.0

16.1.3

15.1.5.1

14.1.5

CVE-2022-35728

F5 BIG-IP ºÍBIG-IQ iControl REST»á»°ÓâÆÚÎó²î

8.1

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

17.0.0

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.5

13.1.0 - 13.1.5

17.0.0.1

16.1.3.1

15.1.6.1

14.1.5.1

BIG-IQ ¼¯ÖÐÖÎÀí

8.0.0 - 8.1.0

7.0.0 - 7.1.0

8.2.0

CVE-2022-34655

F5 BIG-IP TMM ¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.0.0 - 16.0.1

15.1.0 - 15.1.6

14.1.0 - 14.1.4

17.0.0

16.1.0

16.0.1.1

15.1.6.1

14.1.5

CVE-2022-35245

F5 BIG-IP APM »á¼ûÕ½ÂÔÎó²î

7.5

BIG-IP (APM)

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.5

17.0.0

16.1.3.1

15.1.6.1

14.1.5.1

CVE-2022-35240

F5 BIG-IPÐÂÎÅ·ÓÉMQTT¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.2

15.1.0 - 15.1.6

14.1.0 - 14.1.4

17.0.0

16.1.2.2

15.1.6.1

14.1.5

CVE-2022-35236

F5 BIG-IP HTTP2ÉèÖÃÎļþ¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.2

15.1.0 - 15.1.6

14.1.0 - 14.1.4

17.0.0

16.1.2.2

15.1.6.1

14.1.5

CVE-2022-34651

F5 BIG-IP TLS   1.3 iRule ¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.3

15.1.0 - 15.1.6

17.0.0

16.1.3.1

15.1.6.1

CVE-2022-32455

F5 BIG-IP TMM¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.2

15.1.0 - 15.1.6

14.1.0 - 14.1.4

13.1.0 - 13.1.5

17.0.0

16.1.2.2

15.1.6.1

14.1.5

CVE-2022-34862

F5 BIG-IP TMM¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.4

13.1.0 - 13.1.5

17.0.0

16.1.3.1

15.1.6.1

14.1.5

CVE-2022-33203

F5 BIG-IP APM ºÍSSL Orchestrator¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP (APM ºÍSSL Orchestrator)

16.1.0 - 16.1.2

15.1.0 - 15.1.6

14.1.0 - 14.1.4

17.0.0

16.1.3

15.1.6.1

14.1.5

CVE-2022-35272

F5 BIG-IP HTTP   MRF¾Ü¾øÐ§ÀÍÎó²î

7.5

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

17.0.0

16.1.0 - 16.1.3

17.0.0.1

16.1.3.1

CVE-2022-35735

F5 BIG-IP¼àÊÓÆ÷ÉèÖÃȨÏÞÌáÉýÎó²î

7.2

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.5

13.1.0 - 13.1.5

17.0.0

16.1.3.1

15.1.6.1

14.1.5.1

CVE-2022-31473

F5 BIG-IP APM ×°±¸Ä£Ê½Çå¾²ÈÆ¹ýÎó²î£¨iApps Öб£´æÄ¿Â¼±éÀúÎó²î£©

6.8

BIG-IP (APM)

16.1.0

15.1.0 - 15.1.3

17.0.0

16.1.1

15.1.4

CVE-2022-33962

F5 BIG-IP   iRules»á¼û¿ØÖÆÏÞÖÆÈÆ¹ýÎó²î

6.7

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

17.0.0

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.5

13.1.0 - 13.1.5

17.0.0.1

16.1.3.1

15.1.6.1

14.1.5.1

CVE-2022-35241

NGINX ʵÀýÖÎÀíÆ÷¾Ü¾øÐ§ÀÍÎó²î

6.5

NGINX Instance   Manager

2.0.0 - 2.3.0

1.0.0 - 1.0.4

2.3.1

CVE-2022-30535

NGINX Èë¿Ú¿ØÖÆÆ÷ÐÅϢй¶Îó²î

6.5

NGINX Ingress Controller

2.0.0 - 2.2.0

1.0.0 - 1.12.4

2.3.0

CVE-2022-34844

F5 BIG-IP ºÍ BIG-IQ AWS¾Ü¾øÐ§ÀÍÎó²î

5.9

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

16.1.0 - 16.1.3

15.1.0 - 15.1.6

17.0.0

16.1.3.1

15.1.6.1

BIG-IQ ¼¯ÖÐÖÎÀí

8.0.0 - 8.2.0

Null

CVE-2022-33947

BIG-IP DNS TMUI¾Ü¾øÐ§ÀÍÎó²î

5.4

BIG-IP (DNS)

16.0.0 - 16.1.2

15.1.0 - 15.1.6

14.1.0 - 14.1.4

13.1.0 - 13.1.5

17.0.0

16.1.3

15.1.6.1

14.1.5

CVE-2022-34865

F5 BIG-IP   Traffic Intelligence FeedsÖ¤ÊéÑéÖ¤¹ýʧÎó²î

4.8

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

15.1.0 - 15.1.6

14.1.0 - 14.1.4

13.1.0 - 13.1.5

16.1.0

15.1.6.1

14.1.5

CVE-2022-34851

F5 BIG-IP ºÍ BIG-IQ iControl SOAP¾Ü¾øÐ§ÀÍÎó²î

4.3

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

17.0.0

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.5

13.1.0 - 13.1.5

17.0.0.1

16.1.3.1

15.1.6.1

14.1.5.1

BIG-IQ ¼¯ÖÐÖÎÀí

8.0.0 - 8.2.0

Null

CVE-2022-33968

F5 BIG-IP LTM ºÍ APM NTLMÔ½½ç¶ÁÈ¡Îó²î

3.7

BIG-IP£¨ËùÓÐÄ£¿£¿£¿£¿£¿£¿£¿é£©

17.0.0

16.1.0 - 16.1.3

15.1.0 - 15.1.6

14.1.0 - 14.1.5

13.1.0 - 13.1.5

17.0.0.1

16.1.3.1

15.1.6.1

14.1.5.1

ÎÞ

F5 BIG-IP¹¥»÷ÊðÃû¼ì²éÇå¾²Îó²î

Null

BIG-IP   (ASM/AWAF)

16.1.0 - 16.1.2

15.1.0 - 15.1.6

14.1.0 - 14.1.4

13.1.0 - 13.1.5

17.0.0

16.1.2.2

15.1.6.1

14.1.5

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿É²Î¿¼ÉϱíÉý¼¶µ½ÏìÓ¦ÐÞ¸´°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://support.f5.com/csp/home

 

0x03 ²Î¿¼Á´½Ó

https://support.f5.com/csp/article/K14649763

https://support.f5.com/csp/article/K11010341

https://www.cisa.gov/uscert/ncas/current-activity/2022/08/04/f5-releases-security-updates

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-08-05

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬ £¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬠£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬ £¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ £¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ £¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬ £¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬ £¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬ £¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png