Lucene search

K
f5F5F5:K000137353
HistoryOct 26, 2023 - 12:00 a.m.

K000137353 : BIG-IP Configuration utility unauthenticated remote code execution vulnerability CVE-2023-46747

2023-10-2600:00:00
my.f5.com
13
big-ip
unauthenticated
remote code execution
cve-2023-46747
vulnerability
network access
system commands
control plane

AI Score

9.9

Confidence

High

EPSS

0.972

Percentile

99.8%

Security Advisory Description

Undisclosed requests may bypass Configuration utility authentication. (CVE-2023-46747)

Impact

This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. There is no data plane exposure; this is a control plane issue only.