← לוח פגיעויות

CVE-2023-46748

גבוהה 8.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
4% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-89

מוצרים מושפעים

f5: big-ip access policy manager; f5: big-ip advanced firewall manager; f5: big-ip carrier-grade nat; f5: big-ip ddos hybrid defender; f5: big-ip ssl orchestrator; f5: big-ip local traffic manager; f5: big-ip policy enforcement manager; f5: big-ip automation toolchain; f5: big-ip container ingress services; f5: big-ip advanced web application firewall; f5: big-ip domain name system; f5: big-ip application security manager; f5: big-ip analytics; f5: big-ip application acceleration manager; f5: big-ip application visibility and reporting

קישורים