CVE-2026-42924: 
F5 BIG-IP Virtual Edition 脆弱性の分析と軽減

概要

CVE-2026-42924 is a privilege escalation vulnerability in F5 BIG-IP affecting the iControl SOAP interface. An authenticated attacker holding the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP, resulting in privilege escalation beyond their authorized level. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 before 17.1.3.1, 17.5.0 before 17.5.1.4, 21.0.0 before 21.0.0.1, and all 16.1.0 branch versions; software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v4.0 base score of 8.5 (High) and a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).

技術的な詳細

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection), where user-supplied input passed through the iControl SOAP API is not properly sanitized before being used in OS-level operations. An authenticated attacker with the Resource Administrator or Administrator role can craft SNMP configuration object creation requests via iControl SOAP that inject malicious OS command elements, ultimately escalating their privileges on the BIG-IP system. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high-privilege credentials as a precondition. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, F5 Advisory).

影響

Successful exploitation allows an authenticated attacker to escalate privileges beyond their assigned role on the BIG-IP system, resulting in high confidentiality and high integrity impact to the vulnerable system. An attacker who gains elevated privileges could access sensitive configuration data, modify system settings, and potentially pivot to other network resources managed by the BIG-IP appliance. Availability is not directly impacted by this vulnerability, but the integrity and confidentiality compromise of a network appliance like BIG-IP could have significant downstream consequences for the infrastructure it manages (GitHub Advisory, F5 Advisory).

エクスプロイト可能性

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.053% (22nd percentile), indicating a currently low probability of exploitation within the next 30 days. Exploitation requires authenticated access with Resource Administrator or Administrator privileges, which limits the attacker pool but does not eliminate insider threat or credential-compromise scenarios. A Nessus detection plugin (ID 316118) is available for scanning (Tenable).

エクスプロイテーションのステップ

  1. Obtain Credentials: Acquire valid credentials for a BIG-IP account with the Resource Administrator or Administrator role, either through phishing, credential stuffing, or insider access.
  2. Identify Target: Locate an internet-facing or network-accessible F5 BIG-IP instance running a vulnerable version (e.g., 17.1.0–17.1.3.0, 17.5.0–17.5.1.3, 21.0.0, or 16.1.x) using network scanning or Shodan.
  3. Access iControl SOAP Interface: Authenticate to the BIG-IP iControl SOAP API endpoint (typically accessible via HTTPS on the management interface).
  4. Craft Malicious SNMP Configuration Request: Send a specially crafted SOAP request to create an SNMP configuration object, embedding OS command injection payloads within the object parameters that are not properly sanitized.
  5. Achieve Privilege Escalation: The injected OS commands execute with elevated privileges on the BIG-IP system, allowing the attacker to perform actions beyond their assigned role, such as accessing sensitive data or modifying critical system configurations (GitHub Advisory, F5 Advisory).

妥協の兆候

  • Network: Unusual or unexpected SOAP API calls to the BIG-IP iControl SOAP endpoint from non-standard management hosts; SNMP configuration object creation requests originating from accounts not typically performing such actions.
  • Logs: BIG-IP audit logs (/var/log/audit) showing SNMP configuration object creation by Resource Administrator or Administrator accounts at unusual times or from unexpected source IPs; iControl SOAP access logs with anomalous request payloads.
  • Process: Unexpected OS-level processes spawned by the BIG-IP management plane (e.g., shell commands, network utilities) that are not part of normal BIG-IP operations.
  • Configuration: Unauthorized or unexpected changes to SNMP configuration objects in the BIG-IP running configuration; new or modified SNMP community strings, trap destinations, or user accounts.

軽減策と回避策

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Administrators should upgrade to these versions as the primary remediation (F5 Advisory). As interim workarounds, restrict access to the iControl SOAP interface to trusted management hosts only using BIG-IP management port access controls or firewall rules. Additionally, limit assignment of the Resource Administrator and Administrator roles to only personnel who strictly require them, and monitor SNMP configuration object creation activities for unauthorized changes.

コミュニティの反応

The Hacker Wire published a technical article covering the iControl SOAP privilege escalation via SNMP configuration creation shortly after disclosure (The Hacker Wire). The vulnerability was also noted in the CTIPILOT threat intelligence brief for May 17, 2026, alongside other F5 BIG-IP vulnerabilities disclosed in the same advisory cycle. Community reaction has been measured, consistent with the lack of public exploit code and the requirement for pre-existing high-privilege credentials.

関連情報


ソース: このレポートは AI を使用して生成されました

関連 F5 BIG-IP Virtual Edition 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいSep 02, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者