目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1325

100%

CVE-2020-5902— F5 BIG-IP 路径遍历漏洞

AI 预测 9.8 利用难度: 极易 KEV · 勒索软件 EPSS 100.00% · P100
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2020-5902 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
F5 BIG-IP 路径遍历漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
F5 BIG-IP是美国F5公司的一款集成了网络流量管理、应用程序安全管理、负载均衡等功能的应用交付平台。 F5 BIG-IP中存在路径遍历漏洞。攻击者可利用该漏洞执行任意的系统命令、创建或删除文件,关闭服务/执行任意的Java代码,可能完全入侵系统。以下产品及版本受到影响:F5 BIG-IP 15.1.0版本,15.0.0版本,14.1.0版本至14.1.2版本,13.1.0版本至13.1.3版本,12.1.0版本至12.1.5版本,11.6.1版本至11.6.5版本。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商产品影响版本CPE订阅
-BIG-IP 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, 11.6.1-11.6.5.1 -

二、漏洞 CVE-2020-5902 的公开POC

#POC 描述源链接神龙链接
1CVE-2020-5902https://github.com/dwisiswant0/CVE-2020-5902POC详情
2Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.https://github.com/aqhmal/CVE-2020-5902-ScannerPOC详情
3CVE-2020-5902 BIG-IPhttps://github.com/jas502n/CVE-2020-5902POC详情
4POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!https://github.com/ar0dd/CVE-2020-5902POC详情
5Proof of concept for CVE-2020-5902https://github.com/yassineaboukir/CVE-2020-5902POC详情
6Nonehttps://github.com/rwincey/CVE-2020-5902-NSEPOC详情
7Proof of Concept for CVE-2020-5902https://github.com/un4gi/CVE-2020-5902POC详情
8Nonehttps://github.com/nsflabs/CVE-2020-5902POC详情
9exploit code for F5-Big-IP (CVE-2020-5902)https://github.com/yasserjanah/CVE-2020-5902POC详情
10BIG-IP F5 Remote Code Executionhttps://github.com/JSec1337/RCE-CVE-2020-5902POC详情
11Python script to exploit F5 Big-IP CVE-2020-5902 https://github.com/dunderhay/CVE-2020-5902POC详情
12cve-2020-5902 POC exploithttps://github.com/r0ttenbeef/cve-2020-5902POC详情
13Nonehttps://github.com/sv3nbeast/CVE-2020-5902_RCEPOC详情
14CVE-2020-5902 scannerhttps://github.com/cybersecurityworks553/scanner-CVE-2020-5902POC详情
15批量扫描CVE-2020-5902,远程代码执行,已测试https://github.com/lijiaxing1997/CVE-2020-5902-POC-EXPPOC详情
16dummy pochttps://github.com/qlkwej/poc-CVE-2020-5902POC详情
17Nonehttps://github.com/Zinkuth/F5-BIG-IP-CVE-2020-5902POC详情
18Python script to check CVE-2020-5902 (F5 BIG-IP devices).https://github.com/0xAbdullah/CVE-2020-5902POC详情
19CVE-2020-5902https://github.com/jinnywc/CVE-2020-5902POC详情
20Patch F5 appliance CVE-2020-5902https://github.com/GoodiesHQ/F5-PatchPOC详情
21F5 BIG-IP Scanner (CVE-2020-5902)https://github.com/jiansiting/CVE-2020-5902POC详情
22Fix CVE-2020-5902https://github.com/wdlid/CVE-2020-5902-fixPOC详情
23Nonehttps://github.com/Any3ite/CVE-2020-5902-F5BIGPOC详情
24Nonehttps://github.com/k3nundrum/CVE-2020-5902POC详情
25Scan from a given list for F5 BIG-IP and check for CVE-2020-5902https://github.com/inho28/CVE-2020-5902-F5-BIGIPPOC详情
26F5 mass scanner and CVE-2020-5902 checkerhttps://github.com/cristiano-corrado/f5_scannerPOC详情
27POChttps://github.com/ajdumanhug/CVE-2020-5902POC详情
28F5 BIG-IP 任意文件读取+远程命令执行RCEhttps://github.com/zhzyker/CVE-2020-5902POC详情
29It is a small script to fetch out the subdomains/ip vulnerable to CVE-2020-5902 written in bashhttps://github.com/GovindPalakkal/EvilRipPOC详情
30Nonehttps://github.com/dnerzker/CVE-2020-5902POC详情
31A powershell script to check vulnerability CVE-2020-5902 of ip listhttps://github.com/renanhsilva/checkvulnCVE20205902POC详情
32F5 BIG IP Scanner for CVE-2020-5902https://github.com/halencarjunior/f5scanPOC详情
33Script para validar CVE-2020-5902 hecho en Go.https://github.com/deepsecurity-pe/GoF5-CVE-2020-5902POC详情
34Nonehttps://github.com/Shu1L/CVE-2020-5902-fofa-scanPOC详情
35F5 Big-IP CVE-2020-5902 mass exploiter/fuzzer.https://github.com/d4rk007/F5-Big-IP-CVE-2020-5902-mass-exploiterPOC详情
36Simple Vulnerability Checker Wrote by me "@TheCyberViking" and A fellow Researcher who wanted to be left Nameless... you know who you are you beautiful bitchhttps://github.com/TheCyberViking/CVE-2020-5902-Vuln-CheckerPOC详情
37Exploits for CVE-2020-5902 POC https://github.com/itsjeffersonli/CVE-2020-5902POC详情
38Checker CVE-2020-5902: BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1 through 11.6.5.1 suffer from Traffic Management User Interface (TMUI) arbitrary file read and command execution vulnerabilities.https://github.com/MrCl0wnLab/checker-CVE-2020-5902POC详情
39批量检测CVE-2020-5902https://github.com/qiong-qi/CVE-2020-5902-POCPOC详情
40F5 BIG-IP RCE CVE-2020-5902 automatic check toolhttps://github.com/theLSA/f5-bigip-rce-cve-2020-5902POC详情
41CVE-2020-5902https://github.com/Al1ex/CVE-2020-5902POC详情
42Nonehttps://github.com/freeFV/CVE-2020-5902-fofa-scanPOC详情
43Nonehttps://github.com/momika233/cve-2020-5902POC详情
44GUIhttps://github.com/rockmelodies/CVE-2020-5902-rce-guiPOC详情
45Mass exploit for CVE-2020-5902https://github.com/5l1v3r1/CVE-2020-5902-MassPOC详情
46Nonehttps://github.com/f5devcentral/cve-2020-5902-ioc-bigip-checkerPOC详情
47A network detection package for CVE-2020-5902, a CVE10.0 vulnerability affecting F5 Networks, Inc BIG-IP devices.https://github.com/corelight/CVE-2020-5902-F5BigIPPOC详情
48Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3https://github.com/PushpenderIndia/CVE-2020-5902-ScannerPOC详情
49[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)https://github.com/murataydemir/CVE-2020-5902POC详情
50Nonehttps://github.com/superzerosec/cve-2020-5902POC详情
51(CVE-2020-5902) BIG IP F5 TMUI RCE Vulnerability RCE PoC/ Test Script https://github.com/ludy-dev/BIG-IP-F5-TMUI-RCE-VulnerabilityPOC详情
52simple bash script of F5 BIG-IP TMUI Vulnerability CVE-2020-5902 checkerhttps://github.com/faisalfs10x/F5-BIG-IP-CVE-2020-5902-shodan-scannerPOC详情
53Auto exploit RCE CVE-2020-5902 https://github.com/haisenberg/CVE-2020-5902POC详情
54BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerabilityhttps://github.com/z3n70/CVE-2020-5902POC详情
55Nonehttps://github.com/amitlttwo/CVE-2020-5902POC详情
56Exploits for CVE-2020-5902 POC https://github.com/flyopenair/CVE-2020-5902POC详情
57A simple workflow that runs all BigIP related nuclei templates on a given target.https://github.com/projectdiscovery/nuclei-templates/blob/main/workflows/bigip-workflow.yamlPOC详情
58F5 BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5902.yamlPOC详情
59Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/F5%20BIG-IP%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2020-5902.mdPOC详情
60CVE-2020-5902https://github.com/B1ack4sh/Blackash-CVE-2020-5902POC详情
61CVE-2020-5902https://github.com/Ashwesker/Blackash-CVE-2020-5902POC详情
62Script para validar CVE-2020-5902 hecho en Go.https://github.com/DeepSecurity-Pe/GoF5-CVE-2020-5902POC详情
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2020-5902 的情报信息

登录查看更多情报信息。

CVE-2020-5902 厂商安全公告 (2)

CVE-2020-5902 公开利用代码 (5)

CVE-2020-5902 其他参考 (4)

同批安全公告 · n/a · 2020-07-01 · 共 43 条

CVE-2020-76888.4 HIGHmversion 操作系统命令注入漏洞
CVE-2020-76895.9 MEDIUMbcrypt 加密问题漏洞
CVE-2020-12603Envoy 资源管理错误漏洞
CVE-2020-15471Ntop nDPI 缓冲区错误漏洞
CVE-2020-15478Journal theme 信息泄露漏洞
CVE-2020-15472Ntop nDPI 缓冲区错误漏洞
CVE-2020-15475Ntop nDPI 资源管理错误漏洞
CVE-2020-15476Ntop nDPI 缓冲区错误漏洞
CVE-2020-15470ffjpeg 缓冲区错误漏洞
CVE-2020-15468Persian VIP Download Script SQL注入漏洞
CVE-2020-15474Ntop nDPI 缓冲区错误漏洞
CVE-2017-1712HCL Technologies Domino 加密问题漏洞
CVE-2017-1659HCL Technologies Notes 跨站脚本漏洞
CVE-2020-5900F5 NGINX Controller 跨站请求伪造漏洞
CVE-2020-5899F5 NGINX Controller 授权问题漏洞
CVE-2020-5901F5 NGINX Controller 跨站脚本漏洞
CVE-2020-13380Open Solutions for Education openSIS SQL注入漏洞
CVE-2020-13381Open Solutions for Education openSIS SQL注入漏洞
CVE-2020-8663Envoy 资源管理错误漏洞
CVE-2020-13382Open Solutions for Education openSIS 访问控制错误漏洞

显示前 20 条,共 43 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-5902

暂无评论


发表评论