Executive brief
An authenticated SQL injection vulnerability in the F5 BIG-IP Configuration utility allows attackers with network access via the management port or self IP addresses to execute arbitrary system commands. This flaw is known to be exploited in the wild, often in conjunction with CVE-2023-46747.
Affected products
- F5 BIG-IP Configuration utility 13.1.0 - 13.1.5, 14.1.0 - 14.1.5, 15.1.0 - 15.1.10, 16.1.0 - 16.1.4, 17.1.0 - 17.1.1
Timeline
- 2023-10-31: disclosed
- 2023-10-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-10-31: advisory