Security News > 2023 > November > Hackers exploit recent F5 BIG-IP flaws in stealthy attacks

Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
2023-11-01 14:52

F5 is warning BIG-IP admins that devices are being breached by "Skilled" hackers exploiting two recently disclosed vulnerabilities to erase signs of their access and achieve stealthy code execution.

F5 has observed threat actors using the two flaws in combination, so even applying the mitigation for CVE-2023-46747 could be enough to stop most attacks.

F5 fixes BIG-IP auth bypass allowing remote code execution attacks.

Roid October security update fixes zero-days exploited in attacks.

Hackers exploit MinIO storage system to breach corporate networks.

Critical RCE flaws found in SolarWinds access audit solution.


News URL

https://www.bleepingcomputer.com/news/security/hackers-exploit-recent-f5-big-ip-flaws-in-stealthy-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-10-26 CVE-2023-46747 Missing Authentication for Critical Function vulnerability in F5 products
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
network
low complexity
f5 CWE-306
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
F5 141 6 267 399 64 736