{"id":997566,"date":"2023-11-01T19:08:56","date_gmt":"2023-11-01T21:08:56","guid":{"rendered":"https:\/\/teknomers.com\/fr\/alerte-f5-met-en-garde-contre-les-attaques-actives-exploitant-la-vulnerabilite-big-ip\/"},"modified":"2023-11-01T19:09:01","modified_gmt":"2023-11-01T21:09:01","slug":"alerte-f5-met-en-garde-contre-les-attaques-actives-exploitant-la-vulnerabilite-big-ip","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/alerte-f5-met-en-garde-contre-les-attaques-actives-exploitant-la-vulnerabilite-big-ip\/","title":{"rendered":"Alerte\u00a0:\u00a0F5 met en garde contre les attaques actives exploitant la vuln\u00e9rabilit\u00e9 BIG-IP"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">01 novembre 2023<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">R\u00e9daction<\/span><\/span><span class=\"p-tags\">Vuln\u00e9rabilit\u00e9 \/ Cyberattaque<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2023\/11\/Alerte-F5-met-en-garde-contre-les-attaques-actives-exploitant-la.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><\/a><\/div>\n<p>F5 met en garde contre un abus actif d&#8217;une faille de s\u00e9curit\u00e9 critique dans BIG-IP moins d&#8217;une semaine apr\u00e8s sa divulgation publique, entra\u00eenant l&#8217;ex\u00e9cution de commandes syst\u00e8me arbitraires dans le cadre d&#8217;une cha\u00eene d&#8217;exploitation.<\/p>\n<p>Suivi comme <strong>CVE-2023-46747<\/strong> (score CVSS : 9,8), le <a rel=\"nofollow noopener\" href=\"https:\/\/www.praetorian.com\/blog\/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747\/\" target=\"_blank\">vuln\u00e9rabilit\u00e9<\/a> permet \u00e0 un attaquant non authentifi\u00e9 ayant un acc\u00e8s r\u00e9seau au syst\u00e8me BIG-IP via le port de gestion d&#8217;ex\u00e9cuter du code.  Une preuve de concept (PoC) <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/pdnuclei\/status\/1718707055308005468\" target=\"_blank\">exploiter<\/a> a \u00e9t\u00e9 fait depuis <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/projectdiscovery\/nuclei-templates\/pull\/8496\/files\" target=\"_blank\">disponible<\/a> par ProjectDiscovery.<\/p>\n<p>Cela affecte les versions suivantes du logiciel &#8211;<\/p>\n<ul>\n<li>17.1.0 (Corrig\u00e9 dans 17.1.0.3 + Hotfix-BIGIP-17.1.0.3.0.75.4-ENG)<\/li>\n<li>16.1.0 &#8211; 16.1.4 (Corrig\u00e9 dans 16.1.4.1 + Hotfix-BIGIP-16.1.4.1.0.50.5-ENG)<\/li>\n<li>15.1.0 &#8211; 15.1.10 (Corrig\u00e9 dans 15.1.10.2 + Hotfix-BIGIP-15.1.10.2.0.44.2-ENG)<\/li>\n<li>14.1.0 &#8211; 14.1.5 (Corrig\u00e9 dans 14.1.5.6 + Hotfix-BIGIP-14.1.5.6.0.10.6-ENG)<\/li>\n<li>13.1.0 &#8211; 13.1.5 (Corrig\u00e9 dans 13.1.5.1 + Hotfix-BIGIP-13.1.5.1.0.20.2-ENG)<\/li>\n<\/ul>\n<p>Maintenant, l&#8217;entreprise est <a rel=\"nofollow noopener\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000137353\" target=\"_blank\">alerter<\/a> qu&#8217;il a \u00ab observ\u00e9 des acteurs malveillants utilisant cette vuln\u00e9rabilit\u00e9 pour exploiter CVE-2023-46748 \u00bb, qui fait r\u00e9f\u00e9rence \u00e0 une vuln\u00e9rabilit\u00e9 d&#8217;injection SQL authentifi\u00e9e dans l&#8217;utilitaire de configuration BIG-IP.<\/p>\n<div class=\"check_two clear babsi\"><center class=\"cf\"><a rel=\"nofollow noopener\" href=\"https:\/\/thn.news\/pjHvTZON\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"La cyber-s\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2023\/11\/Turla-met-a-jour-la-porte-derobee-Kazuar-avec-une.gif\" width=\"727\" height=\"90\"\/><\/a><\/center><\/div>\n<p>&#8220;Cette vuln\u00e9rabilit\u00e9 peut permettre \u00e0 un attaquant authentifi\u00e9 disposant d&#8217;un acc\u00e8s r\u00e9seau \u00e0 l&#8217;utilitaire de configuration via le port de gestion BIG-IP et\/ou ses propres adresses IP d&#8217;ex\u00e9cuter des commandes syst\u00e8me arbitraires&#8221;, F5 <a rel=\"nofollow noopener\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000137365\" target=\"_blank\">not\u00e9<\/a> dans un avis pour CVE-2023-46748 (score CVSS : 8,8).<\/p>\n<p>En d\u2019autres termes, des acteurs malveillants encha\u00eenent les deux failles pour ex\u00e9cuter des commandes syst\u00e8me arbitraires.  Pour v\u00e9rifier les indicateurs de compromission (IoC) associ\u00e9s \u00e0 la faille d&#8217;injection SQL, il est recommand\u00e9 aux utilisateurs de rechercher dans le fichier \/var\/log\/tomcat\/catalina.out les entr\u00e9es suspectes comme ci-dessous\u00a0:<\/p>\n<pre><i>...\njava.sql.SQLException: Column not found: 0.\n{...)\nsh: no job control in this shell\nsh-4.2$ &lt;EXECUTED SHELL COMMAND&gt;\nsh-4.2$ exit.<\/i><\/pre>\n<p>La Shadowserver Foundation, dans un article sur X (anciennement Twitter), <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/Shadowserver\/status\/1719459765968044378\" target=\"_blank\">dit<\/a> il \u00ab constate des tentatives F5 BIG-IP CVE-2023-46747 dans nos capteurs honeypot \u00bb depuis le 30 octobre 2023, ce qui rend imp\u00e9ratif que les utilisateurs agissent rapidement pour appliquer les correctifs. <\/p>\n<p>Ce d\u00e9veloppement a \u00e9galement encourag\u00e9 l&#8217;Agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures (CISA) \u00e0 <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/10\/31\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">ajouter<\/a> les deux failles de ses vuln\u00e9rabilit\u00e9s exploit\u00e9es connues (<a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>), fond\u00e9 sur des preuves d&#8217;exploitation active.  Les agences f\u00e9d\u00e9rales sont tenues d&#8217;appliquer les correctifs fournis par les fournisseurs d&#8217;ici le 21 novembre 2023.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2023\/11\/alert-f5-warns-of-active-attacks.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80201 novembre 2023\ue804R\u00e9dactionVuln\u00e9rabilit\u00e9 \/ Cyberattaque F5 met en garde contre un abus actif d&#8217;une faille de s\u00e9curit\u00e9 critique dans BIG-IP moins d&#8217;une semaine apr\u00e8s sa divulgation publique, entra\u00eenant l&#8217;ex\u00e9cution de commandes syst\u00e8me arbitraires dans le cadre d&#8217;une cha\u00eene d&#8217;exploitation. Suivi comme CVE-2023-46747 (score CVSS : 9,8), le vuln\u00e9rabilit\u00e9 permet \u00e0 un attaquant non authentifi\u00e9 ayant [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":997567,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[21116,200292,212354,8074,60488,4168,841,4165,4161,200267,29063,525,4159,4171,65,200271,4955,200268,200269,200270,128318,4172,4169,4166,3667,4164],"class_list":["post-997566","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-actives","tag-actualites-sur-la-cybersecurite","tag-alertef5","tag-attaques","tag-bigip","tag-comment-pirater","tag-contre","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-cyberactualites","tag-exploitant","tag-garde","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-les","tag-logiciel-malveillant-rancongiciel","tag-met","tag-mises-a-jour-sur-la-cybersecurite","tag-nouvelles-des-pirates","tag-nouvelles-sur-le-piratage","tag-securite-des-informations","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/997566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=997566"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/997566\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/997567"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=997566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=997566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=997566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}