CVE-2023-46747
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 97% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-288, CWE-306
מוצרים מושפעים
f5: big-ip access policy manager; f5: big-ip advanced firewall manager; f5: big-ip advanced web application firewall; f5: big-ip carrier-grade nat; f5: big-ip ddos hybrid defender; f5: big-ip ssl orchestrator; f5: big-ip domain name system; f5: big-ip local traffic manager; f5: big-ip policy enforcement manager; f5: big-ip automation toolchain; f5: big-ip container ingress services; f5: big-ip application security manager; f5: big-ip analytics; f5: big-ip application acceleration manager; f5: big-ip application visibility and reporting
קישורים
- https://my.f5.com/manage/s/article/K000137353 Vendor Advisory
- https://my.f5.com/manage/s/article/K000137353 Vendor Advisory
- http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remot… ExploitThird Party AdvisoryVDB Entry
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-act… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remot… ExploitThird Party AdvisoryVDB Entry
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-act… ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource