vendor:
BIG-IP
by:
Charles Dardaman and Rich Mirch
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: BIG-IP
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2020-5902
CPE: None
Other Scripts:
N/A
Platforms Tested: None
2020
F5 BIG-IP Remote Code Execution
This exploit allows an attacker to execute arbitrary code on a vulnerable F5 BIG-IP system. It requires Java JDK, hsqldb.jar 1.8, and ysoserial https://jitpack.io/com/github/frohoff/ysoserial/master-SNAPSHOT/ysoserial-master-SNAPSHOT.jar. The exploit uses the ysoserial tool to generate a malicious payload, which is then sent to the vulnerable system. The payload is then executed on the system, allowing the attacker to gain remote code execution.
Mitigation:
F5 has released a security advisory and patch for this vulnerability. Users should update their systems to the latest version of the software to mitigate this vulnerability.