CVE-2023-46747

BIG-IP Configuration utility unauthenticated remote code execution vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
October 25, 2023
Published Date
October 26, 2023
Last Updated
February 13, 2025
Vendor
F5
Product
BIG-IP
Description
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
Total

Exploit Status

Exploited in the Wild
Yes (added 2023-10-31 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2023-11-03 13:31:11 UTC) Source
Used in Malware
Yes (added 2023-10-31 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-10-31 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

f5_bigip_tmui_rce_cve_2023_46747

Type: metasploit • Created: Unknown

Metasploit module for CVE-2023-46747

RevoltSecurities/CVE-2023-46747

Type: github • Created: 2023-11-03 13:31:11 UTC • Stars: 3

An Exploitation script developed to exploit the CVE-2023-46747 which Pre Auth Remote Code Execution of f5-BIG Ip producs

maniak-academy/Mitigate-CVE-2023-46747

Type: github • Created: 2023-11-01 14:57:20 UTC • Stars: 2

W01fh4cker/CVE-2023-46747-RCE

Type: github • Created: 2023-11-01 09:31:05 UTC • Stars: 203

exploit for f5-big-ip RCE cve-2023-46747

AliBrTab/CVE-2023-46747-POC

Type: github • Created: 2023-10-30 15:50:46 UTC • Stars: 9

F5 BIG-IP unauthenticated remote code execution (RCE) and authentication bypass vulnerability!