Vulnerabilities & PatchesEmerging1 src
Issue 184: RCE in F5 BIG-IP suite, API security maturity, hardening GCP implementations
This week, we have news of a high severity remote code execution (RCE) vulnerability in the F5 BIG-IP security suite. We also feature an article from Curity on API security maturity, an article on hardening Google Cloud Platform implementations, and finally a threat matrix for GraphQL APIs.
Vulnerability: RCE vulnerability in F5’s BIG-IP security suite
This week, F5’s BIG-IP load balancing and security suite was affected by a Remote Code Execution (RCE) vulnerability . The vulnerability is in the iControl REST API that allowed remote access to platform configuration. Attackers could gain access to an exposed endpoint /mgmt/tm/util/bash that did not require any authentication.
The vulnerability was given a CVSS score of 9. 8 and is tracked as CVE-2022-1388. F5 have addressed the issue and advised users to patch their systems immediately.