F5 BIG-IP proxy exploitation attempt targeting /mgmt/tm/util/bash (CVE-2023-46747)

Alerts on POST requests containing /mgmt/tm/util/bash plus TMUI control/user-create form parameters indicative of CVE-2023-46747 exploitation.

FreeUnreviewedSigmahighv1
title: F5 BIG-IP proxy exploitation attempt targeting /mgmt/tm/util/bash (CVE-2023-46747)
id: 442e1bb2-92f8-4343-bd4d-356cc372c9ed
related:
  - id: e9928831-ba14-42ea-a4bc-33d352b9929a
    type: similar
  - id: f195b2ff-e542-41bf-8d91-864fb81e5c20
    type: derived
status: test
description: This rule flags HTTP POST traffic to a proxy endpoint containing /mgmt/tm/util/bash along with specific encoded and plain-form application parameters related to /tmui/Control/form and user create.jsp. Such requests are consistent with exploitation attempts seeking unauthenticated remote code execution against vulnerable F5 BIG-IP components. It relies on proxy telemetry capturing HTTP method and request URI, as well as the presence of both the encoded and decoded keyword strings in the request body or captured POST content.
references:
  - https://github.com/AliBrTab/CVE-2023-46747-POC/tree/main
  - https://github.com/0xorOne/nuclei-templates/blob/2fef4270ec6e5573d0a1732cb18bcfc4b1580a88/http/cves/2023/CVE-2023-46747.yaml
  - https://mp.weixin.qq.com/s/wUoBy7ZiqJL2CUOMC-8Wdg
  - https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-46747/proxy_cve_2023_46747_f5_remote_code_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-11-08
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2023-46747
  - detection.emerging-threats
logsource:
  category: proxy
  definition: "Requirements: The POST request body data must be collected in order to make use of this detection"
detection:
  selection:
    cs-method: POST
    c-uri|contains: /mgmt/tm/util/bash
  keywords_hex:
    "|all":
      - 2f746d75692f436f6e74726f6c2f666f726d
      - 666f726d5f706167653d253266746d756925326673797374656d253266757365722532666372656174652e6a7370
  keywords_plain:
    "|all":
      - /tmui/Control/form
      - form_page=%2ftmui%2fsystem%2fuser%2fcreate.jsp
  condition: selection and (keywords_hex or keywords_plain)
falsepositives:
  - Unlikely
level: high
license: DRL-1.1

What it detects

This rule flags HTTP POST traffic to a proxy endpoint containing /mgmt/tm/util/bash along with specific encoded and plain-form application parameters related to /tmui/Control/form and user create.jsp. Such requests are consistent with exploitation attempts seeking unauthenticated remote code execution against vulnerable F5 BIG-IP components. It relies on proxy telemetry capturing HTTP method and request URI, as well as the presence of both the encoded and decoded keyword strings in the request body or captured POST content.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.