CVE-2023-46747 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 96.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-11-21.
Description
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 96.52% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-288 |
| On CISA KEV | yes — remediate by 2023-11-21 |
| Public exploit | none known |
| Published | 2023-10-26 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability |
|---|---|
| Added | 2023-10-31 |
| Due | 2023-11-21 |
| Vendor / product | F5 / BIG-IP Configuration Utility |
| Ransomware use | known |
Affected (20)
| Vendor | Product |
|---|---|
| f5 | big-ip access policy manager |
| f5 | big-ip advanced firewall manager |
| f5 | big-ip advanced web application firewall |
| f5 | big-ip analytics |
| f5 | big-ip application acceleration manager |
| f5 | big-ip application security manager |
| f5 | big-ip application visibility and reporting |
| f5 | big-ip automation toolchain |
| f5 | big-ip carrier-grade nat |
| f5 | big-ip container ingress services |
| f5 | big-ip ddos hybrid defender |
| f5 | big-ip domain name system |
| f5 | big-ip fraud protection services |
| f5 | big-ip global traffic manager |
| f5 | big-ip link controller |
| f5 | big-ip local traffic manager |
| f5 | big-ip policy enforcement manager |
| f5 | big-ip ssl orchestrator |
| f5 | big-ip webaccelerator |
| f5 | big-ip websafe |
References
- http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html
- https://my.f5.com/manage/s/article/K000137353
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/
- http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html
- https://my.f5.com/manage/s/article/K000137353
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46747
→ the Explorer · watch your stack · NVD