← לוח פגיעויות

CVE-2023-46747

קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
97% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-288, CWE-306

מוצרים מושפעים

f5: big-ip access policy manager; f5: big-ip advanced firewall manager; f5: big-ip advanced web application firewall; f5: big-ip carrier-grade nat; f5: big-ip ddos hybrid defender; f5: big-ip ssl orchestrator; f5: big-ip domain name system; f5: big-ip local traffic manager; f5: big-ip policy enforcement manager; f5: big-ip automation toolchain; f5: big-ip container ingress services; f5: big-ip application security manager; f5: big-ip analytics; f5: big-ip application acceleration manager; f5: big-ip application visibility and reporting

קישורים