dfir BleepingComputer

F5 schließt kritische Zero-Day-Lücke in BIG-IP APM: Aktiv für unauthentifizierte Remote-Code-Ausführung auf OAuth-Servern ausgenutzt

F5 hat ein Notfall-Sicherheitsupdate für eine aktiv ausgenutzte Zero-Day-Schwachstelle im BIG-IP APM-Modul veröffentlicht, die unauthentifizierten Angreifern Root-Codeausführung auf OAuth-Servern ermöglicht.

F5 schließt kritische Zero-Day-Lücke in BIG-IP APM: Aktiv für unauthentifizierte Remote-Code-Ausführung auf OAuth-Servern ausgenutzt

Application delivery and network security vendor F5 issued an urgent security bulletin on Wednesday following reports from researchers and cyber defense agencies regarding active zero-day exploitation against systems running BIG-IP APM (Access Policy Manager, an enterprise identity federation, SSL VPN, and access gateway solution). The vulnerability, assigned the maximum CVSS severity rating of 10.0, allows unauthenticated remote adversaries to send crafted HTTP requests to exposed OAuth 2.0 endpoints to achieve instant Remote Code Execution (RCE) with root system privileges.

According to technical advisories published by F5, the flaw stems from improper input validation within the JSON Web Token (JWT) parsing component during token exchange handshakes. By injecting malformed header parameters into incoming authentication requests, attackers can bypass boundary checks and manipulate internal system routines into executing arbitrary Linux shell commands. Because BIG-IP APM serves as the perimeter identity gateway protecting enterprise intranets and cloud resources, an intrusion gives threat actors immediate capability to harvest active session tokens, forge Single Sign-On (SSO) credentials, and pivot laterally across internal network segments without triggering traditional perimeter alerts.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) along with European national CSIRTs confirmed observed in-the-wild exploitation targeting critical infrastructure, defense contractors, and financial institutions over the past 48 hours. F5 strongly urges all system administrators to apply official patches immediately or deploy recommended mitigation filters.

Actionable Guidance for Security Teams

1. Apply Official Patches Immediately: Upgrade all vulnerable BIG-IP appliances to fixed release builds (17.1.1.4, 16.1.4.3, or 15.1.10.5). 2. Restrict Public Exposure to Authentication Endpoints: If immediate patching is not feasible, restrict internet access to the BIG-IP Management interface and place APM OAuth endpoints behind trusted IP access control lists (ACLs). 3. Execute Forensic Log Analysis: Inspect web access logs (`/var/log/apm` and `/var/log/httpd/access_log`) for abnormal POST requests directed at `/oauth/v1/token` containing anomalous payload sizes or nested Base64 command strings. 4. Revoke and Rotate OAuth Signing Keys: If unauthorized requests are identified, terminate all active user sessions, rotate OAuth client secrets, and regenerate SAML/SSO signing certificates.

Evidence Rail

  • Confirmed: F5 published Security Advisory K000142981 confirming unauthenticated root RCE vulnerability.
  • Reported: CISA and threat intelligence telemetry confirm active exploitation in the wild across multiple critical sectors.
  • Unconfirmed: Precise attribution to specific threat actor clusters (nation-state APT vs. cybercriminal broker) remains under ongoing investigation.

In Brief

  • Critical CVSS 10.0 zero-day in F5 BIG-IP APM enables unauthenticated remote root code execution.
  • Threat actors actively targeting enterprise OAuth and identity federation endpoints globally.
  • Immediate patching, access restriction, and forensic log triage required for all exposed deployments.

Quellen & Referenzen

← Alle Nachrichten Werkzeuge