F5 BIG-IP TMUI Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-5902£© ·À»¤¼Æ»®
2020-07-06
Ò». ×ÛÊö
¿ËÈÕ£¬F5¹Ù·½Ðû²¼Í¨¸æ£¬ÐÞ¸´ÁËÁ÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©Öб£´æµÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-5902£©¡£´ËÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ò¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýBIG-IPÖÎÀí¶Ë¿ÚºÍ/»ò×ÔÉíIP¶ÔTMUI¾ÙÐÐÍøÂç»á¼û£¬ÒÔÖ´ÐÐí§ÒâϵͳÏÂÁî¡¢½¨Éè»òɾ³ýÎļþ¡¢½ûÓ÷þÎñºÍ/»òÖ´ÐÐí§ÒâJava´úÂë¡£¸ÃÎó²î¿ÉÄܶÔÕû¸öϵͳÔì³ÉΣº¦¡£ÏÖÔÚ¼à²âµ½ÍøÂçÉÏÒѾÓÐPoC£¬²¢ÇÒÒÑÓÐʹÓøÃÎó²îµÄ¹¥»÷ÐÐΪ·ºÆð£¬½¨ÒéÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤¡£
F5 BIG-IP ÊÇÃÀ¹ú F5 ¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢Ó¦ÓóÌÐòÇå¾²ÖÎÀí¡¢¸ºÔØÆ½ºâµÈ¹¦Ð§µÄÓ¦Óý»¸¶Æ½Ì¨¡£
²Î¿¼Á´½Ó£º
https://support.f5.com/csp/article/K52145254
¶þ. Îó²îÓ°Ïì¹æÄ£
F5 BIG-IP 15.x ÒÑÖªÒ×Êܹ¥»÷°æ±¾ 15.1.0¡¢15.0.0
F5 BIG-IP 14.x ÒÑÖªÒ×Êܹ¥»÷°æ±¾ 14.1.0-14.1.2
F5 BIG-IP 13.x ÒÑÖªÒ×Êܹ¥»÷°æ±¾ 13.1.0-13.1.3
F5 BIG-IP 12.x ÒÑÖªÒ×Êܹ¥»÷°æ±¾ 12.1.0-12.1.5
F5 BIG-IP 11.x ÒÑÖªÒ×Êܹ¥»÷°æ±¾ 11.6.1-11.6.5
Èý. ÊÖÒÕ·À»¤¼Æ»®
3.1 ¹Ù·½ÐÞ¸´¼Æ»®
F5¹Ù·½ÒѾÐû²¼×îа汾ÐÞ¸´Á˸ÃÎó²î£¬ÊÜÓ°ÏìµÄÓû§Ó¦¾¡¿ìÉý¼¶¾ÙÐзÀ»¤¡£
F5 BIG-IP 15.1.0.4
F5 BIG-IP 14.1.2.6
F5 BIG-IP 13.1.3.4
F5 BIG-IP 12.1.5.2
F5 BIG-IP 11.6.5.2
3.2 »º½â²½·¥
ÔÝʱ²»Àû±ãÉý¼¶µÄÓû§¿ÉÒÔ½ÓÄÉÒÔÏÂÔÝʱ»º½â²½·¥£º
1. ÊäÈëÒÔÏÂÏÂÁîµÇ¼µ½TMOS Shell£¨tmsh£©£ºtmsh
2. ÊäÈëÒÔÏÂÏÂÁîÀ´±à¼httpdÊôÐÔ£º
edit /sys httpd all-properties
3. ½«ÎļþÖÐ<include>²¿·Ö¸ÄΪÏÂÁÐÄÚÈÝ£º
include '
<LocationMatch ".*\.\.;.*">
Redirect 404 /
</LocationMatch>
'
4. ÊäÈëÒÔÏÂÏÂÁ¸ü¸ÄдÈëÉèÖÃÎļþ²¢ÉúÑÄ£º
Esc
:wq!
5. ÊäÈëÒÔÏÂÏÂÁîÉúÑÄÉèÖãº
save /sys config
6£®ÊäÈëÒÔÏÂÏÂÁîÖØÐÂÆô¶¯httpd·þÎñ£º
restart sys service httpd
Óë´Ëͬʱ£¬Õ¥È¡ÍⲿIP¹ØÓÚTMUIµÄ»á¼û£¬»òÖ»ÔÊÐíÖÎÀíÖ°Ô±ÔÚÇå¾²ÍøÂçÇéÐÎÏ»á¼ûÀ´»º½âÎó²î¡£
https://support.f5.com/csp/article/K52145254
3.3 AG¹«Ë¾¿Æ¼¼¼ì²â·À»¤½¨Òé
3.3.1 AG¹«Ë¾¿Æ¼¼¼ì²âÀà²úÆ·Óë·þÎñ
ÄÚÍø×ʲú¿ÉÒÔʹÓÃAG¹«Ë¾¿Æ¼¼µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©¡¢WebÓ¦ÓÃÎó²îɨÃèϵͳ£¨WVSS£©¡£
l Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©http://update.nsfocus.com/update/listRsas
l WebÓ¦ÓÃÎó²îɨÃèϵͳ£¨WVSS£©http://update.nsfocus.com/update/listWvss
3.3.1.1 ¼ì²â²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ
|
¼ì²â²úÆ· |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
|
RSAS V6 ϵͳ²å¼þ |
6.0R02F01.1902 |
|
RSAS V6 Web²å¼þ |
6.0R02F00.1801 |
|
WVSS V6 ²å¼þ |
6.0R03F00.167 |
l RSAS V6 ϵͳ²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/106313
l RSAS V6 Web²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/106314
l WVSS V6²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/106312
3.3.2 AG¹«Ë¾¿Æ¼¼·À»¤Àà²úÆ·
ʹÓÃAG¹«Ë¾¿Æ¼¼·À»¤Àà²úÆ·£¬WebÓ¦Ó÷À»¤ÏµÍ³£¨WAF£©À´¾ÙÐзÀ»¤¡£
l WebÓ¦Ó÷À»¤ÏµÍ³£¨WAF£©
http://update.nsfocus.com/update/wafIndex
3.3.2.1 ·À»¤²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ
|
·À»¤²úÆ· |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
¹æÔò±àºÅ |
|
WAF |
WAF ÒÔǰµÄ¹æÔò¼´¿É·À»¤ Éý¼¶°ü°æ±¾£º 6.0.7.0.45556¡¢6.0.4.1.45556¡¢ 6.0.7.1.45556 |
27526188 |
ËÄ. ¸½Â¼A ²úƷʹÓÃÖ¸ÄÏ
4.1 RSASɨÃèÉèÖÃ
ÔÚϵͳÉý¼¶ÖУ¬µã»÷ÏÂͼºì¿òλÖÃÑ¡ÔñÎļþ¡£

Ñ¡ÔñÏÂÔØºÃµÄÏìÓ¦Éý¼¶°ü£¬µã»÷Éý¼¶°´Å¥¾ÙÐÐÊÖ¶¯Éý¼¶¡£ÆÚ´ýÉý¼¶Íê³Éºó£¬¿Éͨ¹ý¶¨ÖÆÉ¨ÃèÄ£°å£¬Õë¶Ô´Ë´ÎÎó²î¾ÙÐÐɨÃè¡£
4.2 WVSSɨÃèÉèÖÃ
ÔÚWVSSµÄϵͳÉý¼¶½çÃæ£¬µã»÷ÏÂͼºì¿òλÖÃÑ¡ÔñÎļþ£¬¾ÙÐÐÉý¼¶£º

Ñ¡ÔñÏÂÔØºÃµÄÏìÓ¦Éý¼¶°ü£¬µã»÷Éý¼¶°´Å¥¾ÙÐÐÊÖ¶¯Éý¼¶¡£ÆÚ´ýÉý¼¶Íê³Éºó£¬¿Éͨ¹ý¶¨ÖÆÉ¨ÃèÄ£°å£¬Õë¶Ô´Ë´ÎÎó²î¾ÙÐÐɨÃè¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







