{"id":142062,"date":"2022-05-12T14:51:19","date_gmt":"2022-05-12T16:51:19","guid":{"rendered":"https:\/\/teknomers.com\/fr\/la-cisa-exhorte-les-organisations-a-corriger-la-vulnerabilite-f5-big-ip-activement-exploitee\/"},"modified":"2022-05-12T14:51:24","modified_gmt":"2022-05-12T16:51:24","slug":"la-cisa-exhorte-les-organisations-a-corriger-la-vulnerabilite-f5-big-ip-activement-exploitee","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/la-cisa-exhorte-les-organisations-a-corriger-la-vulnerabilite-f5-big-ip-activement-exploitee\/","title":{"rendered":"La CISA exhorte les organisations \u00e0 corriger la vuln\u00e9rabilit\u00e9 F5 BIG-IP activement exploit\u00e9e"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis a <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/05\/10\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\">ajout\u00e9e<\/a> la faille F5 BIG-IP r\u00e9cemment r\u00e9v\u00e9l\u00e9e \u00e0 son <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues<\/a> \u00e0 la suite de rapports d&#8217;abus actifs dans la nature.<\/p>\n<p>La faille, affect\u00e9e de l&#8217;identifiant CVE-2022-1388 (score CVSS : 9,8), concerne un <a rel=\"nofollow noopener\" href=\"https:\/\/www.randori.com\/blog\/vulnerability-analysis-cve-2022-1388\/\" target=\"_blank\">bogue critique<\/a> dans le point de terminaison BIG-IP iControl REST qui fournit \u00e0 un adversaire non authentifi\u00e9 une m\u00e9thode pour ex\u00e9cuter des commandes syst\u00e8me arbitraires.<\/p>\n<p>&#8220;Un attaquant peut utiliser cette vuln\u00e9rabilit\u00e9 pour faire \u00e0 peu pr\u00e8s tout ce qu&#8217;il veut sur le serveur vuln\u00e9rable&#8221;, Horizon3.ai <a rel=\"nofollow noopener\" href=\"https:\/\/www.horizon3.ai\/f5-icontrol-rest-endpoint-authentication-bypass-technical-deep-dive\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un rapport.  &#8220;Cela inclut la modification de la configuration, le vol d&#8217;informations sensibles et le d\u00e9placement lat\u00e9ral au sein du r\u00e9seau cible.&#8221;<\/p>\n<p>Des correctifs et des att\u00e9nuations pour la faille ont \u00e9t\u00e9 annonc\u00e9s par F5 le 4 mai, mais il a \u00e9t\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/1ZRR4H\/status\/1523572874061422593\" target=\"_blank\">soumis<\/a> pour <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/bad_packets\/status\/1523740777406377985\" target=\"_blank\">dans la nature<\/a> <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/sans_isc\/status\/1523732455546494976\" target=\"_blank\">exploitation<\/a> au cours de la semaine derni\u00e8re, les attaquants tentant d&#8217;installer un shell Web qui accorde un acc\u00e8s par porte d\u00e9rob\u00e9e aux syst\u00e8mes cibl\u00e9s.<\/p>\n<p>&#8220;En raison de la facilit\u00e9 d&#8217;exploitation de cette vuln\u00e9rabilit\u00e9, du code d&#8217;exploitation public et du fait qu&#8217;il fournit un acc\u00e8s root, les tentatives d&#8217;exploitation sont susceptibles d&#8217;augmenter&#8221;, a d\u00e9clar\u00e9 Ron Bowes, chercheur en s\u00e9curit\u00e9 chez Rapid7. <a rel=\"nofollow noopener\" href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/05\/09\/active-exploitation-of-f5-big-ip-icontrol-rest-cve-2022-1388\/\" target=\"_blank\">c&#8217;est not\u00e9<\/a>.  &#8220;L&#8217;exploitation g\u00e9n\u00e9ralis\u00e9e est quelque peu att\u00e9nu\u00e9e par la <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/Junior_Baines\/status\/1522205355287228416\" target=\"_blank\">Petit nombre<\/a> d&#8217;appareils F5 BIG-IP connect\u00e9s \u00e0 Internet.&#8221;<\/p>\n<p>Bien que F5 ait depuis r\u00e9vis\u00e9 son avis pour y inclure ce qu&#8217;il consid\u00e8re comme des indicateurs de compromission &#8220;fiables&#8221;, il a <a rel=\"nofollow noopener\" href=\"https:\/\/support.f5.com\/csp\/article\/K23605346\" target=\"_blank\">mis en garde<\/a> qu'&#8221;un attaquant qualifi\u00e9 peut supprimer les preuves de compromission, y compris les fichiers journaux, apr\u00e8s une exploitation r\u00e9ussie&#8221;.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Pour empirer les choses, <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/sans_isc\/status\/1523741896707043328\" target=\"_blank\">preuve<\/a> poss\u00e8de <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1524160730114764801\" target=\"_blank\">a \u00e9merg\u00e9<\/a> que la faille d&#8217;ex\u00e9cution de code \u00e0 distance est utilis\u00e9e pour effacer compl\u00e8tement les serveurs cibl\u00e9s dans le cadre d&#8217;attaques destructrices afin de les rendre inop\u00e9rants en \u00e9mettant un &#8220;<a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Rm_(Unix)#Syntax\" target=\"_blank\">rm -rf \/*<\/a>&#8221; commande qui supprime r\u00e9cursivement tous les fichiers.<\/p>\n<p>&#8220;\u00c9tant donn\u00e9 que le serveur Web s&#8217;ex\u00e9cute en tant que root, cela devrait prendre en charge tout serveur vuln\u00e9rable et d\u00e9truire tout appareil BIG-IP vuln\u00e9rable&#8221;, a d\u00e9clar\u00e9 SANS Internet Storm Center (ISC). <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/sans_isc\/status\/1523742317059792896\" target=\"_blank\">mentionn\u00e9<\/a> sur Twitter.<\/p>\n<p>\u00c0 la lumi\u00e8re de l&#8217;impact potentiel de cette vuln\u00e9rabilit\u00e9, les agences du Pouvoir ex\u00e9cutif civil f\u00e9d\u00e9ral (FCEB) ont \u00e9t\u00e9 mandat\u00e9es pour corriger tous les syst\u00e8mes contre le probl\u00e8me d&#8217;ici le 31 mai 2022.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/05\/cisa-urges-organizations-to-patch.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis a ajout\u00e9e la faille F5 BIG-IP r\u00e9cemment r\u00e9v\u00e9l\u00e9e \u00e0 son Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues \u00e0 la suite de rapports d&#8217;abus actifs dans la nature. La faille, affect\u00e9e de l&#8217;identifiant CVE-2022-1388 (score CVSS : 9,8), concerne un bogue critique dans le point de terminaison BIG-IP iControl [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":142063,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4807,60488,4805,4168,25646,4158,4165,4161,8055,36372,4157,4159,4171,4170,65,4167,4160,4163,4162,12070,4172,4169,4166,3667,4164],"class_list":["post-142062","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-activement","tag-bigip","tag-cisa","tag-comment-pirater","tag-corriger","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-exhorte","tag-exploitee","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-organisations","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/142062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=142062"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/142062\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/142063"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=142062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=142062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=142062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}