CVE-2023-46747
Description
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Summary dbcve.org
This is a critical authentication bypass vulnerability in F5 BIG-IP's configuration utility. Undisclosed requests can bypass authentication, allowing remote attackers with network access to the management port or self IP addresses to execute arbitrary system commands with elevated privileges.
Mitigation
Apply the vendor-supplied security patch for BIG-IP immediately and restrict network access to the management interface and self IP addresses to trusted sources only.