CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 25, 2023
- Published Date
- October 26, 2023
- Last Updated
- February 13, 2025
- Vendor
- F5
- Product
- BIG-IP
- Description
- Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- Total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-10-31 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/f5_bigip_tmui_rce_cve_2023_46747.rb | 2025-04-29 11:01:12 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-46747.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
f5_bigip_tmui_rce_cve_2023_46747
Type: metasploit • Created: Unknown
RevoltSecurities/CVE-2023-46747
Type: github • Created: 2023-11-03 13:31:11 UTC • Stars: 3
maniak-academy/Mitigate-CVE-2023-46747
Type: github • Created: 2023-11-01 14:57:20 UTC • Stars: 2
W01fh4cker/CVE-2023-46747-RCE
Type: github • Created: 2023-11-01 09:31:05 UTC • Stars: 203
AliBrTab/CVE-2023-46747-POC
Type: github • Created: 2023-10-30 15:50:46 UTC • Stars: 9