EXPOSURES › CVE-2023-46747
CVE-2023-46747
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated attacker can bypass BIG-IP Configuration Utility authentication to execute system commands.
F5 BIG-IP Configuration Utility allows unauthenticated attackers to execute system commands via an authentication bypass, enabling full system compromise. This is critical for DIB orgs because it directly violates access control and system integrity requirements, allowing lateral movement and data exfiltration. Organizations must patch immediately and restrict management port access.
Shame score — A critical authentication bypass allowing unauthenticated command execution is a severe, avoidable failure that directly enables ransomware and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.