F5 BIG-IP proxy exploitation attempt targeting /mgmt/tm/util/bash (CVE-2023-46747)
Alerts on POST requests containing /mgmt/tm/util/bash plus TMUI control/user-create form parameters indicative of CVE-2023-46747 exploitation.
FreeUnreviewedSigmahighv1
f5-big-ip-proxy-exploitation-attempt-targeting-mgmt-tm-util-bash-cve-2023-46747-f195b2ff
title: F5 BIG-IP proxy exploitation attempt targeting /mgmt/tm/util/bash (CVE-2023-46747)
id: 442e1bb2-92f8-4343-bd4d-356cc372c9ed
related:
- id: e9928831-ba14-42ea-a4bc-33d352b9929a
type: similar
- id: f195b2ff-e542-41bf-8d91-864fb81e5c20
type: derived
status: test
description: This rule flags HTTP POST traffic to a proxy endpoint containing /mgmt/tm/util/bash along with specific encoded and plain-form application parameters related to /tmui/Control/form and user create.jsp. Such requests are consistent with exploitation attempts seeking unauthenticated remote code execution against vulnerable F5 BIG-IP components. It relies on proxy telemetry capturing HTTP method and request URI, as well as the presence of both the encoded and decoded keyword strings in the request body or captured POST content.
references:
- https://github.com/AliBrTab/CVE-2023-46747-POC/tree/main
- https://github.com/0xorOne/nuclei-templates/blob/2fef4270ec6e5573d0a1732cb18bcfc4b1580a88/http/cves/2023/CVE-2023-46747.yaml
- https://mp.weixin.qq.com/s/wUoBy7ZiqJL2CUOMC-8Wdg
- https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-46747/proxy_cve_2023_46747_f5_remote_code_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-11-08
tags:
- attack.initial-access
- attack.t1190
- cve.2023-46747
- detection.emerging-threats
logsource:
category: proxy
definition: "Requirements: The POST request body data must be collected in order to make use of this detection"
detection:
selection:
cs-method: POST
c-uri|contains: /mgmt/tm/util/bash
keywords_hex:
"|all":
- 2f746d75692f436f6e74726f6c2f666f726d
- 666f726d5f706167653d253266746d756925326673797374656d253266757365722532666372656174652e6a7370
keywords_plain:
"|all":
- /tmui/Control/form
- form_page=%2ftmui%2fsystem%2fuser%2fcreate.jsp
condition: selection and (keywords_hex or keywords_plain)
falsepositives:
- Unlikely
level: high
license: DRL-1.1
What it detects
This rule flags HTTP POST traffic to a proxy endpoint containing /mgmt/tm/util/bash along with specific encoded and plain-form application parameters related to /tmui/Control/form and user create.jsp. Such requests are consistent with exploitation attempts seeking unauthenticated remote code execution against vulnerable F5 BIG-IP components. It relies on proxy telemetry capturing HTTP method and request URI, as well as the presence of both the encoded and decoded keyword strings in the request body or captured POST content.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.