CVE-2023-46748 KEV
8.8
HIGH · CVSS 3.1 · EPSS 4.5% (pctl 91)
Patch first
On CISA KEV — known exploited in the wild, due 2023-11-21.
Description
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.47% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | yes — remediate by 2023-11-21 |
| Public exploit | none known |
| Published | 2023-10-26 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | F5 BIG-IP Configuration Utility SQL Injection Vulnerability |
|---|---|
| Added | 2023-10-31 |
| Due | 2023-11-21 |
| Vendor / product | F5 / BIG-IP Configuration Utility |
| Ransomware use | none reported |
Affected (20)
| Vendor | Product |
|---|---|
| f5 | big-ip access policy manager |
| f5 | big-ip advanced firewall manager |
| f5 | big-ip advanced web application firewall |
| f5 | big-ip analytics |
| f5 | big-ip application acceleration manager |
| f5 | big-ip application security manager |
| f5 | big-ip application visibility and reporting |
| f5 | big-ip automation toolchain |
| f5 | big-ip carrier-grade nat |
| f5 | big-ip container ingress services |
| f5 | big-ip ddos hybrid defender |
| f5 | big-ip domain name system |
| f5 | big-ip fraud protection services |
| f5 | big-ip global traffic manager |
| f5 | big-ip link controller |
| f5 | big-ip local traffic manager |
| f5 | big-ip policy enforcement manager |
| f5 | big-ip ssl orchestrator |
| f5 | big-ip webaccelerator |
| f5 | big-ip websafe |
References
- https://my.f5.com/manage/s/article/K000137365
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/
- https://my.f5.com/manage/s/article/K000137365
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46748
→ the Explorer · watch your stack · NVD