Lucene search

K
nvd[email protected]NVD:CVE-2023-46747
HistoryOct 26, 2023 - 9:15 p.m.

CVE-2023-46747

2023-10-2621:15:08
CWE-306
CWE-288
web.nvd.nist.gov
7
undisclosed requests
authentication bypass
arbitrary commands
network access
big-ip system
management port
self ip addresses

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.972

Percentile

99.8%

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.Β Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected configurations

Nvd
Node
f5big-ip_access_policy_managerRange13.1.0–13.1.5
OR
f5big-ip_access_policy_managerRange14.1.0–14.1.5
OR
f5big-ip_access_policy_managerRange15.1.0–15.1.10
OR
f5big-ip_access_policy_managerRange16.1.0–16.1.4
OR
f5big-ip_access_policy_managerRange17.1.0–17.1.1
Node
f5big-ip_advanced_firewall_managerRange13.1.0–13.1.5
OR
f5big-ip_advanced_firewall_managerRange14.1.0–14.1.5
OR
f5big-ip_advanced_firewall_managerRange15.1.0–15.1.10
OR
f5big-ip_advanced_firewall_managerRange16.1.0–16.1.4
OR
f5big-ip_advanced_firewall_managerRange17.1.0–17.1.1
Node
f5big-ip_advanced_web_application_firewallRange13.1.0–13.1.5
OR
f5big-ip_advanced_web_application_firewallRange14.1.0–14.1.5
OR
f5big-ip_advanced_web_application_firewallRange15.1.0–15.1.10
OR
f5big-ip_advanced_web_application_firewallRange16.1.0–16.1.4
OR
f5big-ip_advanced_web_application_firewallRange17.1.0–17.1.1
Node
f5big-ip_carrier-grade_natRange13.1.0–13.1.5
OR
f5big-ip_carrier-grade_natRange14.1.0–14.1.5
OR
f5big-ip_carrier-grade_natRange15.1.0–15.1.10
OR
f5big-ip_carrier-grade_natRange16.1.0–16.1.4
OR
f5big-ip_carrier-grade_natRange17.1.0–17.1.1
Node
f5big-ip_ddos_hybrid_defenderRange13.1.0–13.1.5
OR
f5big-ip_ddos_hybrid_defenderRange14.1.0–14.1.5
OR
f5big-ip_ddos_hybrid_defenderRange15.1.0–15.1.10
OR
f5big-ip_ddos_hybrid_defenderRange16.1.0–16.1.4
OR
f5big-ip_ddos_hybrid_defenderRange17.1.0–17.1.1
Node
f5big-ip_ssl_orchestratorRange13.1.0–13.1.5
OR
f5big-ip_ssl_orchestratorRange14.1.0–14.1.5
OR
f5big-ip_ssl_orchestratorRange15.1.0–15.1.10
OR
f5big-ip_ssl_orchestratorRange16.1.0–16.1.4
OR
f5big-ip_ssl_orchestratorRange17.1.0–17.1.1
Node
f5big-ip_domain_name_systemRange13.1.0–13.1.5
OR
f5big-ip_domain_name_systemRange14.1.0–14.1.5
OR
f5big-ip_domain_name_systemRange15.1.0–15.1.10
OR
f5big-ip_domain_name_systemRange16.1.0–16.1.4
OR
f5big-ip_domain_name_systemRange17.1.0–17.1.1
Node
f5big-ip_local_traffic_managerRange13.1.0–13.1.5
OR
f5big-ip_local_traffic_managerRange14.1.0–14.1.5
OR
f5big-ip_local_traffic_managerRange15.1.0–15.1.10
OR
f5big-ip_local_traffic_managerRange16.1.0–16.1.4
OR
f5big-ip_local_traffic_managerRange17.1.0–17.1.1
Node
f5big-ip_policy_enforcement_managerRange13.1.0–13.1.5
OR
f5big-ip_policy_enforcement_managerRange14.1.0–14.1.5
OR
f5big-ip_policy_enforcement_managerRange15.1.0–15.1.10
OR
f5big-ip_policy_enforcement_managerRange16.1.0–16.1.4
OR
f5big-ip_policy_enforcement_managerRange17.1.0–17.1.1
Node
f5big-ip_automation_toolchainRange13.1.0–13.1.5
OR
f5big-ip_automation_toolchainRange14.1.0–14.1.5
OR
f5big-ip_automation_toolchainRange15.1.0–15.1.10
OR
f5big-ip_automation_toolchainRange16.1.0–16.1.4
OR
f5big-ip_automation_toolchainRange17.1.0–17.1.1
Node
f5big-ip_container_ingress_servicesRange13.1.0–13.1.5
OR
f5big-ip_container_ingress_servicesRange14.1.0–14.1.5
OR
f5big-ip_container_ingress_servicesRange15.1.0–15.1.10
OR
f5big-ip_container_ingress_servicesRange16.1.0–16.1.4
OR
f5big-ip_container_ingress_servicesRange17.1.0–17.1.1
Node
f5big-ip_application_security_managerRange13.1.0–13.1.5
OR
f5big-ip_application_security_managerRange14.1.0–14.1.5
OR
f5big-ip_application_security_managerRange15.1.0–15.1.10
OR
f5big-ip_application_security_managerRange16.1.0–16.1.4
OR
f5big-ip_application_security_managerRange17.1.0–17.1.1
Node
f5big-ip_analyticsRange13.1.0–13.1.5
OR
f5big-ip_analyticsRange14.1.0–14.1.5
OR
f5big-ip_analyticsRange15.1.0–15.1.10
OR
f5big-ip_analyticsRange16.1.0–16.1.4
OR
f5big-ip_analyticsRange17.1.0–17.1.1
Node
f5big-ip_application_acceleration_managerRange13.1.0–13.1.5
OR
f5big-ip_application_acceleration_managerRange14.1.0–14.1.5
OR
f5big-ip_application_acceleration_managerRange15.1.0–15.1.10
OR
f5big-ip_application_acceleration_managerRange16.1.0–16.1.4
OR
f5big-ip_application_acceleration_managerRange17.1.0–17.1.1
Node
f5big-ip_application_visibility_and_reportingRange13.1.0–13.1.5
OR
f5big-ip_application_visibility_and_reportingRange14.1.0–14.1.5
OR
f5big-ip_application_visibility_and_reportingRange15.1.0–15.1.10
OR
f5big-ip_application_visibility_and_reportingRange16.1.0–16.1.4
OR
f5big-ip_application_visibility_and_reportingRange17.1.0–17.1.1
Node
f5big-ip_fraud_protection_servicesRange13.1.0–13.1.5
OR
f5big-ip_fraud_protection_servicesRange14.1.0–14.1.5
OR
f5big-ip_fraud_protection_servicesRange15.1.0–15.1.10
OR
f5big-ip_fraud_protection_servicesRange16.1.0–16.1.4
OR
f5big-ip_fraud_protection_servicesRange17.1.0–17.1.1
Node
f5big-ip_global_traffic_managerRange13.1.0–13.1.5
OR
f5big-ip_global_traffic_managerRange14.1.0–14.1.5
OR
f5big-ip_global_traffic_managerRange15.1.0–15.1.10
OR
f5big-ip_global_traffic_managerRange16.1.0–16.1.4
OR
f5big-ip_global_traffic_managerRange17.1.0–17.1.1
Node
f5big-ip_link_controllerRange13.1.0–13.1.5
OR
f5big-ip_link_controllerRange14.1.0–14.1.5
OR
f5big-ip_link_controllerRange15.1.0–15.1.10
OR
f5big-ip_link_controllerRange16.1.0–16.1.4
OR
f5big-ip_link_controllerRange17.1.0–17.1.1
Node
f5big-ip_webacceleratorRange13.1.0–13.1.5
OR
f5big-ip_webacceleratorRange14.1.0–14.1.5
OR
f5big-ip_webacceleratorRange15.1.0–15.1.10
OR
f5big-ip_webacceleratorRange16.1.0–16.1.4
OR
f5big-ip_webacceleratorRange17.1.0–17.1.1
Node
f5big-ip_websafeRange13.1.0–13.1.5
OR
f5big-ip_websafeRange14.1.0–14.1.5
OR
f5big-ip_websafeRange15.1.0–15.1.10
OR
f5big-ip_websafeRange16.1.0–16.1.4
OR
f5big-ip_websafeRange17.1.0–17.1.1
VendorProductVersionCPE
f5big-ip_access_policy_manager*cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager*cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
f5big-ip_advanced_web_application_firewall*cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
f5big-ip_carrier-grade_nat*cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
f5big-ip_ddos_hybrid_defender*cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
f5big-ip_ssl_orchestrator*cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
f5big-ip_domain_name_system*cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
f5big-ip_local_traffic_manager*cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager*cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
f5big-ip_automation_toolchain*cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.972

Percentile

99.8%