Article 5Z1T9 Hackers are actively exploiting BIG-IP vulnerability with a 9.8 severity rating

Hackers are actively exploiting BIG-IP vulnerability with a 9.8 severity rating

by
Dan Goodin
from Ars Technica - All content on (#5Z1T9)
enterprise-network-800x534.jpeg

Enlarge

Researchers are marveling at the scope and magnitude of a vulnerability that hackers are actively exploiting to take full control of network devices that run on some of the world's biggest and most sensitive networks.

The vulnerability, which carries a 9.8 severity rating out of a possible 10, affects F5's BIG-IP, a line of appliances that organizations use as load balancers, firewalls, and for inspection and encryption of data passing into and out of networks. There are more than 16,000 instances of the gear discoverable online, and F5 says it's used by 48 of the Fortune 50. Given BIG-IP's proximity to network edges and their functions as devices that manage traffic for web servers, they often are in a position to see decrypted contents of HTTPS-protected traffic.

Last week, F5 disclosed and patched a BIG-IP vulnerability that hackers can exploit to execute commands that run with root system privileges. The threat stems from a faulty authentication implementation of the iControl REST, a set of web-based programming interfaces for configuring and managing BIG-IP devices.

Read 5 remaining paragraphs | Comments

index?i=AMFSUVSdw8g:-hdmhAaBEw8:V_sGLiPB index?i=AMFSUVSdw8g:-hdmhAaBEw8:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments