CVE-2023-46747: BIG-IP Configuration utility unauthenticated remote code execution vulnerability
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.
Other sources
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.1.1.117.1.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1.4.216.1.4.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1.10.315.1.10.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.1.5.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.1.5.1 - Upgrade
Upgrade
F5 BIG-IP Configuration Utilityto a version that resolves this vulnerability.Fixed in 13.1.5.1 - Upgrade
Upgrade
F5 BIG-IP Configuration Utilityto a version that resolves this vulnerability.Fixed in 14.1.5.6 - Upgrade
Upgrade
F5 BIG-IP Configuration Utilityto a version that resolves this vulnerability.Fixed in 15.1.10.315.1.10.2 - Upgrade
Upgrade
F5 BIG-IP Configuration Utilityto a version that resolves this vulnerability.Fixed in 16.1.4.216.1.4.1 - Upgrade
Upgrade
F5 BIG-IP Configuration Utilityto a version that resolves this vulnerability.Fixed in 17.1.1.117.1.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-46747?
CVE-2023-46747 is a vulnerability in the BIG-IP Configuration utility that allows unauthenticated remote code execution.
How severe is CVE-2023-46747?
CVE-2023-46747 has a severity rating of 9.8 (Critical).
What software is affected by CVE-2023-46747?
The F5 BIG-IP Configuration utility is affected by CVE-2023-46747.
Is authentication required for exploitation of CVE-2023-46747?
No, CVE-2023-46747 allows an attacker to bypass authentication and execute code without authentication.
How can I fix CVE-2023-46747?
To fix CVE-2023-46747, update the BIG-IP Configuration utility to the latest version provided by F5.