Skip to content
COOEY

EXPOSURES › CVE-2023-46747

CVE-2023-46747

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-31 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-46747 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildrcenegligence

An unauthenticated attacker can bypass BIG-IP Configuration Utility authentication to execute system commands.

F5 BIG-IP Configuration Utility allows unauthenticated attackers to execute system commands via an authentication bypass, enabling full system compromise. This is critical for DIB orgs because it directly violates access control and system integrity requirements, allowing lateral movement and data exfiltration. Organizations must patch immediately and restrict management port access.

Shame score — A critical authentication bypass allowing unauthenticated command execution is a severe, avoidable failure that directly enables ransomware and data breaches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.