Record summary

CVE-2023-46748 has a selected CVSS score of 8.8 (high). CISA lists CVE-2023-46748 in KEV.

Description

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 31, 2023 · CISA
VulnCheck KEV
Listed · Oct 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List17.1.0 to < *affected
16.1.0 to < *affected
15.1.0 to < *affected
14.1.0 to < *affected
13.1.0 to < *affected

BIG-IP Configuration Utility

Browse F5 / BIG-IP Configuration Utility
CISAVersion data not supplied

References

4