my.f5.comVendor advisory
https://my.f5.com/manage/s/article/K000137365 CVE-2023-46748
HIGHCISA KEV
BIG-IP Configuration utility authenticated SQL injection vulnerability
Record summary
CVE-2023-46748 has a selected CVSS score of 8.8 (high). CISA lists CVE-2023-46748 in KEV.
Description
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Oct 31, 2023 · CISA
- VulnCheck KEV
- Listed · Oct 30, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
BIG-IPBrowse F5 / BIG-IPDefault status: unknown | CVE List | 17.1.0 to < * | affected |
| 16.1.0 to < * | affected | ||
| 15.1.0 to < * | affected | ||
| 14.1.0 to < * | affected | ||
| 13.1.0 to < * | affected | ||
BIG-IP Configuration UtilityBrowse F5 / BIG-IP Configuration Utility | CISA | Version data not supplied | |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-46748 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46748 secpod.com
https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain