Hackers can use a leaked SSH key to obtain root access on many F5 networking appliances An exploit for a recently patched vulnerability that allows potential attackers to obtain administrative access on network appliances from hardware vendor F5 Networks was added to the Metasploit penetration testing framework on Tuesday.In a security advisory published on June 6, F5 Networks advised customers that attackers could exploit a SSH configuration error to obtain root access on many of its products.The vulnerable platforms are VIPRION B2100, B4100, B4200; Enterprise Manager 3000, 4000; BIG-IP 520, 540, 1000, 2000, 2400, 5000, 5100, 1600, 3600, 3900, 6900, 8900, 8950, 11000, 11050; and BIG-IP Virtual Edition. SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe The vulnerability is the result of a SSH private key present in many F5 appliances being publicly available. This key allows unauthorized users to bypass authentication and login as root on those devices, Florent Daigniere, the security researcher who discovered the issue, said in a separate advisory. Users of the affected products should install the software updates and hotfixes made available by F5 as soon as possible, especially since exploit code for this vulnerability is now publicly available.F5 also released a SSH reconfiguration tool that can be used by customers that cannot immediately deploy the security patches, to prevent the compromised SSH key from working. Instructions on how to use this tool, as well as apply other mitigation techniques, are described in F5’s advisory. The vulnerability is identified as CVE-2012-1493 and was rated as highly critical by security firm Secunia because it can result in a full system compromise and can be attacked remotely. Related content feature Gen AI success starts with an effective pilot strategy To harness the promise of generative AI, IT leaders must develop processes for identifying use cases, educate employees, and get the tech (safely) into their hands. By Bob Violino Sep 27, 2023 10 mins Generative AI Innovation Emerging Technology feature A fluency in business and tech yields success at NATO Manfred Boudreaux-Dehmer speaks with Lee Rennick, host of CIO Leadership Live, Canada, about innovation in technology, leadership across a vast cultural landscape, and what it means to hold the inaugural CIO role at NATO. By CIO staff Sep 27, 2023 6 mins CIO IT Skills Innovation feature The demand for new skills: How can CIOs optimize their team? By Andrea Benito Sep 27, 2023 3 mins opinion The CIO event of the year: What to expect at CIO100 ASEAN Awards By Shirin Robert Sep 26, 2023 3 mins IDG Events IT Leadership Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe