CVE-2026-42937: 
F5 BIG-IP Virtual Edition 脆弱性の分析と軽減

概要

CVE-2026-42937 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products, specifically in the TMOS Shell (tmsh) arp and ndp commands and in BIG-IP iControl REST. The vulnerability allows an authenticated attacker with low privileges to view adjacent network information that should be restricted to higher privilege levels. It was published on May 13, 2026, with a patch made available the same day. Affected versions include BIG-IP 16.1.0 and later (up to fixed versions), BIG-IP 17.1.0 < 17.1.3.2, BIG-IP 17.5.0 < 17.5.1.6, BIG-IP 21.0.0 < 21.0.0.2, and BIG-IQ 8.4.0 and later. The CVSS v3.1 base score is 6.5 (Medium) and the CVSS v4.0 base score is 7.1 (High) (GitHub Advisory, F5 Advisory).

技術的な詳細

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where the arp and ndp commands in the BIG-IP/BIG-IQ TMOS Shell and the iControl REST API are configured with permissions that allow lower-privileged authenticated users to access information intended only for higher-privileged roles. An attacker with valid, low-privilege credentials can invoke these commands or REST endpoints over the network without any user interaction, obtaining adjacent network topology data such as ARP and NDP table entries. No special attack complexity or prerequisites beyond valid credentials are required (GitHub Advisory, F5 Advisory).

影響

Successful exploitation results in unauthorized disclosure of adjacent network information, including ARP and NDP table data, which could reveal network topology, IP-to-MAC address mappings, and neighboring device details. There is no integrity or availability impact — the vulnerability is limited to confidentiality. While the scope is constrained to adjacent network information, this data could assist an attacker in further reconnaissance or lateral movement within the network environment (GitHub Advisory, F5 Advisory).

エクスプロイト可能性

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041–0.051%, placing it in the 16th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported.

エクスプロイテーションのステップ

  1. Obtain valid credentials: Acquire low-privilege authenticated credentials for a BIG-IP or BIG-IQ system running an affected version (e.g., through phishing, credential stuffing, or insider access).
  2. Access tmsh or iControl REST: Log in to the TMOS Shell (tmsh) via SSH or access the iControl REST API endpoint using the obtained credentials.
  3. Execute restricted commands: Run the arp or ndp commands within tmsh, or issue equivalent iControl REST API requests (e.g., GET /mgmt/tm/net/arp or GET /mgmt/tm/net/ndp) that should be restricted to higher-privilege roles.
  4. Collect adjacent network information: Review the output, which reveals ARP/NDP table entries including IP addresses, MAC addresses, and interface associations of adjacent network devices.
  5. Use data for further reconnaissance: Leverage the disclosed network topology information to identify additional targets or plan lateral movement within the network (GitHub Advisory, F5 Advisory).

妥協の兆候

  • Logs: BIG-IP audit logs showing low-privilege user accounts executing arp or ndp commands in tmsh; iControl REST access logs recording GET requests to /mgmt/tm/net/arp or /mgmt/tm/net/ndp by accounts not expected to access these endpoints.
  • Network: Unusual or repeated REST API queries to ARP/NDP endpoints from authenticated sessions associated with low-privilege service or operator accounts.
  • Behavioral: Low-privilege user accounts accessing network information commands outside of normal administrative workflows or at unusual times.

軽減策と回避策

F5 has released patched versions: BIG-IP 17.1.3.2, 17.5.1.6, and 21.0.0.2. Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, restrict access to tmsh arp and ndp commands and iControl REST endpoints to only users who legitimately require access to adjacent network information, and audit user role assignments to enforce least-privilege principles (F5 Advisory, GitHub Advisory).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 F5 BIG-IP Virtual Edition 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいSep 02, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者