POLICY-OTHER --
POLICY-OTHER F5 iControl REST interface tm.util.bash invocation attempt
This rule looks for attempts to invoke the "tm.util.bash" function in F5 iControl. Attackers with access to this endpoint can execute arbitrary commands on the F5 server.
This rule looks for attempts to invoke the "tm.util.bash" function in F5 iControl.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
Command Injection
Command Injection attacks target applications that allow unsafe user-supplied input. Attackers transmit this input via forms, cookies, HTTP headers, etc. and exploit the applications permissions to execute system commands without injecting code.
CVE-2022-1388 |
Loading description
|
Tactic: Initial Access
Technique: Exploit Public-Facing Application
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org