目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2020-5902— F5 BIG-IP 路径遍历漏洞

KEV · ランサムウェア EPSS 94.43% · P100
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2020-5902の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
N/A
ソース: NVD (National Vulnerability Database)
脆弱性説明
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
ソース: NVD (National Vulnerability Database)
CVSS情報
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
F5 BIG-IP 路径遍历漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
F5 BIG-IP是美国F5公司的一款集成了网络流量管理、应用程序安全管理、负载均衡等功能的应用交付平台。 F5 BIG-IP中存在路径遍历漏洞。攻击者可利用该漏洞执行任意的系统命令、创建或删除文件,关闭服务/执行任意的Java代码,可能完全入侵系统。以下产品及版本受到影响:F5 BIG-IP 15.1.0版本,15.0.0版本,14.1.0版本至14.1.2版本,13.1.0版本至13.1.3版本,12.1.0版本至12.1.5版本,11.6.1版本至11.6.5版本。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

Shenlong 10 Questions — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
-BIG-IP 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, 11.6.1-11.6.5.1 -

II. CVE-2020-5902の公開POC

#POC説明ソースリンクShenlongリンク
1CVE-2020-5902https://github.com/dwisiswant0/CVE-2020-5902POC詳細
2Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.https://github.com/aqhmal/CVE-2020-5902-ScannerPOC詳細
3CVE-2020-5902 BIG-IPhttps://github.com/jas502n/CVE-2020-5902POC詳細
4POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!https://github.com/ar0dd/CVE-2020-5902POC詳細
5Proof of concept for CVE-2020-5902https://github.com/yassineaboukir/CVE-2020-5902POC詳細
6Nonehttps://github.com/rwincey/CVE-2020-5902-NSEPOC詳細
7Proof of Concept for CVE-2020-5902https://github.com/un4gi/CVE-2020-5902POC詳細
8Nonehttps://github.com/nsflabs/CVE-2020-5902POC詳細
9exploit code for F5-Big-IP (CVE-2020-5902)https://github.com/yasserjanah/CVE-2020-5902POC詳細
10BIG-IP F5 Remote Code Executionhttps://github.com/JSec1337/RCE-CVE-2020-5902POC詳細
11Python script to exploit F5 Big-IP CVE-2020-5902 https://github.com/dunderhay/CVE-2020-5902POC詳細
12cve-2020-5902 POC exploithttps://github.com/r0ttenbeef/cve-2020-5902POC詳細
13Nonehttps://github.com/sv3nbeast/CVE-2020-5902_RCEPOC詳細
14CVE-2020-5902 scannerhttps://github.com/cybersecurityworks553/scanner-CVE-2020-5902POC詳細
15批量扫描CVE-2020-5902,远程代码执行,已测试https://github.com/lijiaxing1997/CVE-2020-5902-POC-EXPPOC詳細
16dummy pochttps://github.com/qlkwej/poc-CVE-2020-5902POC詳細
17Nonehttps://github.com/Zinkuth/F5-BIG-IP-CVE-2020-5902POC詳細
18Python script to check CVE-2020-5902 (F5 BIG-IP devices).https://github.com/0xAbdullah/CVE-2020-5902POC詳細
19CVE-2020-5902https://github.com/jinnywc/CVE-2020-5902POC詳細
20Patch F5 appliance CVE-2020-5902https://github.com/GoodiesHQ/F5-PatchPOC詳細
21F5 BIG-IP Scanner (CVE-2020-5902)https://github.com/jiansiting/CVE-2020-5902POC詳細
22Fix CVE-2020-5902https://github.com/wdlid/CVE-2020-5902-fixPOC詳細
23Nonehttps://github.com/Any3ite/CVE-2020-5902-F5BIGPOC詳細
24Nonehttps://github.com/k3nundrum/CVE-2020-5902POC詳細
25Scan from a given list for F5 BIG-IP and check for CVE-2020-5902https://github.com/inho28/CVE-2020-5902-F5-BIGIPPOC詳細
26F5 mass scanner and CVE-2020-5902 checkerhttps://github.com/cristiano-corrado/f5_scannerPOC詳細
27POChttps://github.com/ajdumanhug/CVE-2020-5902POC詳細
28F5 BIG-IP 任意文件读取+远程命令执行RCEhttps://github.com/zhzyker/CVE-2020-5902POC詳細
29It is a small script to fetch out the subdomains/ip vulnerable to CVE-2020-5902 written in bashhttps://github.com/GovindPalakkal/EvilRipPOC詳細
30Nonehttps://github.com/dnerzker/CVE-2020-5902POC詳細
31A powershell script to check vulnerability CVE-2020-5902 of ip listhttps://github.com/renanhsilva/checkvulnCVE20205902POC詳細
32F5 BIG IP Scanner for CVE-2020-5902https://github.com/halencarjunior/f5scanPOC詳細
33Script para validar CVE-2020-5902 hecho en Go.https://github.com/deepsecurity-pe/GoF5-CVE-2020-5902POC詳細
34Nonehttps://github.com/Shu1L/CVE-2020-5902-fofa-scanPOC詳細
35F5 Big-IP CVE-2020-5902 mass exploiter/fuzzer.https://github.com/d4rk007/F5-Big-IP-CVE-2020-5902-mass-exploiterPOC詳細
36Simple Vulnerability Checker Wrote by me "@TheCyberViking" and A fellow Researcher who wanted to be left Nameless... you know who you are you beautiful bitchhttps://github.com/TheCyberViking/CVE-2020-5902-Vuln-CheckerPOC詳細
37Exploits for CVE-2020-5902 POC https://github.com/itsjeffersonli/CVE-2020-5902POC詳細
38Checker CVE-2020-5902: BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1 through 11.6.5.1 suffer from Traffic Management User Interface (TMUI) arbitrary file read and command execution vulnerabilities.https://github.com/MrCl0wnLab/checker-CVE-2020-5902POC詳細
39批量检测CVE-2020-5902https://github.com/qiong-qi/CVE-2020-5902-POCPOC詳細
40F5 BIG-IP RCE CVE-2020-5902 automatic check toolhttps://github.com/theLSA/f5-bigip-rce-cve-2020-5902POC詳細
41CVE-2020-5902https://github.com/Al1ex/CVE-2020-5902POC詳細
42Nonehttps://github.com/freeFV/CVE-2020-5902-fofa-scanPOC詳細
43Nonehttps://github.com/momika233/cve-2020-5902POC詳細
44GUIhttps://github.com/rockmelodies/CVE-2020-5902-rce-guiPOC詳細
45Mass exploit for CVE-2020-5902https://github.com/5l1v3r1/CVE-2020-5902-MassPOC詳細
46Nonehttps://github.com/f5devcentral/cve-2020-5902-ioc-bigip-checkerPOC詳細
47A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.https://github.com/corelight/CVE-2020-5902-F5BigIPPOC詳細
48Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3https://github.com/PushpenderIndia/CVE-2020-5902-ScannerPOC詳細
49[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)https://github.com/murataydemir/CVE-2020-5902POC詳細
50Nonehttps://github.com/superzerosec/cve-2020-5902POC詳細
51(CVE-2020-5902) BIG IP F5 TMUI RCE Vulnerability RCE PoC/ Test Script https://github.com/ludy-dev/BIG-IP-F5-TMUI-RCE-VulnerabilityPOC詳細
52simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checkerhttps://github.com/faisalfs10x/F5-BIG-IP-CVE-2020-5902-shodan-scannerPOC詳細
53Auto exploit RCE CVE-2020-5902 https://github.com/haisenberg/CVE-2020-5902POC詳細
54BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerabilityhttps://github.com/z3n70/CVE-2020-5902POC詳細
55Nonehttps://github.com/amitlttwo/CVE-2020-5902POC詳細
56Exploits for CVE-2020-5902 POC https://github.com/flyopenair/CVE-2020-5902POC詳細
57A simple workflow that runs all BigIP related nuclei templates on a given target.https://github.com/projectdiscovery/nuclei-templates/blob/main/workflows/bigip-workflow.yamlPOC詳細
58F5 BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5902.yamlPOC詳細
59Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/F5%20BIG-IP%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2020-5902.mdPOC詳細
60CVE-2020-5902https://github.com/B1ack4sh/Blackash-CVE-2020-5902POC詳細
61CVE-2020-5902https://github.com/Ashwesker/Blackash-CVE-2020-5902POC詳細
62Script para validar CVE-2020-5902 hecho en Go.https://github.com/DeepSecurity-Pe/GoF5-CVE-2020-5902POC詳細
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2020-5902のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-07-01 · 43 CVEs total

CVE-2020-76888.4 HIGHCommand Injection
CVE-2020-76895.9 MEDIUMInsecure Encryption
CVE-2020-12603Envoy 资源管理错误漏洞
CVE-2020-15471Ntop nDPI 缓冲区错误漏洞
CVE-2020-15478Journal theme 信息泄露漏洞
CVE-2020-15472Ntop nDPI 缓冲区错误漏洞
CVE-2020-15475Ntop nDPI 资源管理错误漏洞
CVE-2020-15476Ntop nDPI 缓冲区错误漏洞
CVE-2020-15470ffjpeg 缓冲区错误漏洞
CVE-2020-15468Persian VIP Download Script SQL注入漏洞
CVE-2020-15474Ntop nDPI 缓冲区错误漏洞
CVE-2017-1712HCL Technologies Domino 加密问题漏洞
CVE-2017-1659HCL Technologies Notes 跨站脚本漏洞
CVE-2020-5900F5 NGINX Controller 跨站请求伪造漏洞
CVE-2020-5899F5 NGINX Controller 授权问题漏洞
CVE-2020-5901F5 NGINX Controller 跨站脚本漏洞
CVE-2020-13380Open Solutions for Education openSIS SQL注入漏洞
CVE-2020-13381Open Solutions for Education openSIS SQL注入漏洞
CVE-2020-8663Envoy 资源管理错误漏洞
CVE-2020-13382Open Solutions for Education openSIS 访问控制错误漏洞

Showing 20 of 43 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2020-5902へのコメント

まだコメントはありません


コメントを残す