CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
Description
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
In plain language
AI Act nowCVE-2023-46747 is a BIG-IP flaw where an attacker who can reach your network-facing BIG-IP can run commands on it without logging in; this is RED and you should act now if your BIG-IP is reachable from the network.
CVE-2023-46747 is an unauthenticated remote command execution flaw in the BIG-IP configuration utility; it allows remote attackers who can reach the BIG-IP management port or self IP addresses to bypass authentication and execute arbitrary system commands.
What to do now
- Check whether your BIG-IP management interface or self IPs are reachable from untrusted networks (especially the internet or third-party networks).
- Identify your BIG-IP software version and compare it to the vendor’s guidance for CVE-2023-46747 (use the vendor link in the message below).
- If exposure is possible, immediately apply F5’s recommended mitigations from their article for CVE-2023-46747, or take the device offline/discontinue use if mitigations are unavailable.
- Plan and perform the BIG-IP update/upgrade path the vendor specifies for your version line to remove the unauthenticated command execution risk.
- After changes, verify that the management access paths involved (management port / self IP reachability) are no longer reachable from untrusted sources and confirm normal operation.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-46747 and every CVE in our database. Create a free account — no credit card required.
Create Free Account