Junglewise Threat Intelligence

CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

CVE-2023-46748 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-10-31

Vendors: F5.

Executive brief

An authenticated SQL injection vulnerability in the F5 BIG-IP Configuration utility allows attackers with network access via the management port or self IP addresses to execute arbitrary system commands. This flaw is known to be exploited in the wild, often in conjunction with CVE-2023-46747.

Affected products

  • F5 BIG-IP Configuration utility 13.1.0 - 13.1.5, 14.1.0 - 14.1.5, 15.1.0 - 15.1.10, 16.1.0 - 16.1.4, 17.1.0 - 17.1.1

Timeline

  • 2023-10-31: disclosed
  • 2023-10-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-31: advisory

Related threats