Junglewise Threat Intelligence

CVE-2023-46747: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

CVE-2023-46747 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-10-31

Vendors: F5.

Executive brief

F5 BIG-IP Configuration utility contains an authentication bypass vulnerability via undisclosed requests. An unauthenticated attacker with network access to the BIG-IP system through the management port or self IP addresses can bypass authentication to execute arbitrary system commands.

Affected products

  • F5 BIG-IP Configuration Utility 13.1.0 - 13.1.5, 14.1.0 - 14.1.5, 15.1.0 - 15.1.10, 16.1.0 - 16.1.4, 17.1.0 - 17.1.1

Timeline

  • 2023-10-31: disclosed
  • 2023-10-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-31: advisory: Published by F5 Networks

Related threats