Executive brief
F5 BIG-IP Configuration utility contains an authentication bypass vulnerability via undisclosed requests. An unauthenticated attacker with network access to the BIG-IP system through the management port or self IP addresses can bypass authentication to execute arbitrary system commands.
Affected products
- F5 BIG-IP Configuration Utility 13.1.0 - 13.1.5, 14.1.0 - 14.1.5, 15.1.0 - 15.1.10, 16.1.0 - 16.1.4, 17.1.0 - 17.1.1
Timeline
- 2023-10-31: disclosed
- 2023-10-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-10-31: advisory: Published by F5 Networks