Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in F5 BIG-IP APM when configured as an OAuth Authorization Server, potentially allowing unauthenticated attackers to achieve remote code execution. This issue impacts the data plane and requires careful assessment of its relevance to our specific deployments.
- An attacker can execute code remotely.
- Critical flaw affects public-facing authentication.
- Confirm relevance and exposure for our systems.
Attack Path
How an attacker could exploit the issue
An attacker can trigger this vulnerability by sending specific malicious traffic to a BIG-IP system that has both an APM access policy and an OAuth profile configured on a virtual server. This requires the BIG-IP APM to be set up as an OAuth Authorization Server. If successful, this could allow the attacker to execute code remotely on the system.
- No authentication needed.
- Malicious traffic to the system.
- Remote code execution.
Live Threat
Current exploitation, exposure, and threat context
When BIG-IP APM is configured as an OAuth Authorization Server, specific malicious traffic could lead to remote code execution on the appliance. This is a data plane issue, meaning it affects the operational functions of the system rather than its administrative interfaces, and is only present under specific configuration conditions.
- Asset at risk: BIG-IP system, data plane.
- How exposure could happen: Unauthenticated malicious traffic.
- Realistic consequence: Remote code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The BIG-IP APM product, specifically when configured as an OAuth Authorization Server, presents a critical risk. Owners of these systems, likely infrastructure or platform teams, must first identify all instances of BIG-IP APM used in this capacity. Confirming whether these instances are exposed externally and handle business-critical functions is paramount. Subsequently, collaboration with security and vendor management teams will be necessary to plan and execute risk-based remediation.
- Platform and infrastructure teams own this.
- Verify external reachability and business criticality.
- Plan vendor-coordinated remediation actions.