CVE-2023-46748
KEV PoC largeAuthenticated SQL Injection in F5 BIG-IP Configuration Utility
CISA: F5 BIG-IP Configuration Utility SQL Injection Vulnerability
CVE-2023-46748 is an authenticated SQL injection (CWE-89) in the F5 BIG-IP Configuration utility. An attacker who holds valid credentials and can reach the utility over the BIG-IP management port or self IP addresses can submit crafted input that escapes a SQL query and executes arbitrary system commands on the appliance. Successful exploitation yields high-impact compromise of the affected BIG-IP system (CVSS 3.1: 8.8), giving the attacker command execution on the platform that load-balances, filters, or inspects an organization's traffic. Any organization running a supported (non-End-of-Technical-Support) BIG-IP deployment of the listed modules — LTM, APM, ASM, Advanced WAF, DNS, AFM, CGNAT, DDoS Hybrid Defender, SSL Orchestrator, PEM, Automation Toolchain or Container Ingress Services — is in scope, since the Configuration utility is a core BIG-IP component. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-31 after F5 warned of active attacks, including exploit chains involving the related CVE-2023-46747 (which has a public PoC); EPSS currently rates 30-day exploitation probability at ~4.5% (91st percentile), and ransomware involvement is unconfirmed.
What to do: Apply F5's software updates for CVE-2023-46748 on every affected BIG-IP system per vendor instructions, prioritizing appliances whose Configuration utility is reachable via the management port or self IPs from untrusted networks; if patching must wait, restrict management/self-IP access to trusted networks and verify no weak or default credentials exist. Because the flaw is in CISA's KEV and used in active exploit chains (including chains with CVE-2023-46747, which has a public PoC), hunt for anomalous Configuration utility sessions and unexpected system commands, and confirm you are not running an End-of-Technical-Support release that F5 no longer evaluates.
| f5 BIG-IP Configuration Utility (vulnerable component per CISA; shipped with all listed BIG-IP modules) | — |
| f5 BIG-IP Local Traffic Manager (LTM) | — |
| f5 BIG-IP Access Policy Manager (APM) | — |
| f5 BIG-IP Application Security Manager (ASM) | — |
| f5 BIG-IP Advanced Web Application Firewall (Advanced WAF) | — |
| f5 BIG-IP Domain Name System (DNS) | — |
| f5 BIG-IP Advanced Firewall Manager (AFM) | — |
| f5 BIG-IP Carrier-Grade NAT (CGNAT) | — |
| f5 BIG-IP DDoS Hybrid Defender | — |
| f5 BIG-IP SSL Orchestrator | — |
| f5 BIG-IP Policy Enforcement Manager (PEM) | — |
| f5 BIG-IP Automation Toolchain | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- Affected
- F5 BIG-IP Configuration Utility
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- f5
- Products
- big-ip access policy manager, big-ip advanced firewall manager, big-ip carrier-grade nat, big-ip ddos hybrid defender, big-ip ssl orchestrator, big-ip local traffic manager, big-ip policy enforcement manager, big-ip automation toolchain, big-ip container ingress services, big-ip advanced web application firewall, big-ip domain name system, big-ip application security manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H