CVE-2023-46748: BIG-IP Configuration utility authenticated SQL injection vulnerability
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Other sources
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 17.1.1.1 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 16.1.4.2 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 15.1.10.3 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 14.1.5.6 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 13.1.5.1
Event History
Frequently Asked Questions
What is CVE-2023-46748?
CVE-2023-46748 is a vulnerability that allows an authenticated attacker to execute arbitrary system commands in the BIG-IP Configuration utility.
How severe is the BIG-IP Configuration utility authenticated SQL injection vulnerability (CVE-2023-46748)?
The severity of CVE-2023-46748 is high with a CVSS score of 8.8.
How does the BIG-IP Configuration utility authenticated SQL injection vulnerability (CVE-2023-46748) affect F5 BIG-IP Configuration utility?
CVE-2023-46748 affects F5 BIG-IP Configuration utility, allowing an authenticated attacker to execute arbitrary system commands.
How can I fix the BIG-IP Configuration utility authenticated SQL injection vulnerability (CVE-2023-46748)?
To fix CVE-2023-46748, apply the provided security patch or update to the latest version of the F5 BIG-IP Configuration utility.
Where can I find more information about the BIG-IP Configuration utility authenticated SQL injection vulnerability (CVE-2023-46748)?
You can find more information about CVE-2023-46748 in the reference article: https://my.f5.com/manage/s/article/K000137365