vendor:
BIG-IP
by:
Dave Kennedy (ReL1K)
8,8
CVSS
HIGH
Authentication Bypass
287 (Authentication Bypass)
CWE
Product Name: BIG-IP
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
Unknown
F5 BIG-IP Remote Root Authentication Bypass Vulnerability (py)
This exploit allows an attacker to bypass authentication and gain root access to the F5 BIG-IP appliance. The exploit involves writing a private RSA key to a file, then using the SSH command to connect to the appliance as root. The exploit was written by Dave Kennedy (ReL1K) and was published on his website secmaniac.com.
Mitigation:
The best way to mitigate this vulnerability is to ensure that the F5 BIG-IP appliance is running the latest version of the software and that all security patches are applied.