CRITICAL

CVE-2023-46747

F5 Big Ip Access Policy Manager 2023-10-26 CVSS v3.1
CVSS
9.8
KEV

Description

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Summary dbcve.org

This is a critical authentication bypass vulnerability in F5 BIG-IP's configuration utility. Undisclosed requests can bypass authentication, allowing remote attackers with network access to the management port or self IP addresses to execute arbitrary system commands with elevated privileges.

Mitigation

Apply the vendor-supplied security patch for BIG-IP immediately and restrict network access to the management interface and self IP addresses to trusted sources only.

Proof of Concept

Weakness (CWE)

CWE-288
CWE-306 Missing Authentication

EPSS Score

96.52%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE