ZeroHour

CVE-2023-46748

KEV PoC large

Authenticated SQL Injection in F5 BIG-IP Configuration Utility

CISA: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
4%p91
Published
()
KEV added
AI analysis

CVE-2023-46748 is an authenticated SQL injection (CWE-89) in the F5 BIG-IP Configuration utility. An attacker who holds valid credentials and can reach the utility over the BIG-IP management port or self IP addresses can submit crafted input that escapes a SQL query and executes arbitrary system commands on the appliance. Successful exploitation yields high-impact compromise of the affected BIG-IP system (CVSS 3.1: 8.8), giving the attacker command execution on the platform that load-balances, filters, or inspects an organization's traffic. Any organization running a supported (non-End-of-Technical-Support) BIG-IP deployment of the listed modules — LTM, APM, ASM, Advanced WAF, DNS, AFM, CGNAT, DDoS Hybrid Defender, SSL Orchestrator, PEM, Automation Toolchain or Container Ingress Services — is in scope, since the Configuration utility is a core BIG-IP component. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-31 after F5 warned of active attacks, including exploit chains involving the related CVE-2023-46747 (which has a public PoC); EPSS currently rates 30-day exploitation probability at ~4.5% (91st percentile), and ransomware involvement is unconfirmed.

What to do: Apply F5's software updates for CVE-2023-46748 on every affected BIG-IP system per vendor instructions, prioritizing appliances whose Configuration utility is reachable via the management port or self IPs from untrusted networks; if patching must wait, restrict management/self-IP access to trusted networks and verify no weak or default credentials exist. Because the flaw is in CISA's KEV and used in active exploit chains (including chains with CVE-2023-46747, which has a public PoC), hunt for anomalous Configuration utility sessions and unexpected system commands, and confirm you are not running an End-of-Technical-Support release that F5 no longer evaluates.

Affected
f5 BIG-IP Configuration Utility (vulnerable component per CISA; shipped with all listed BIG-IP modules)
f5 BIG-IP Local Traffic Manager (LTM)
f5 BIG-IP Access Policy Manager (APM)
f5 BIG-IP Application Security Manager (ASM)
f5 BIG-IP Advanced Web Application Firewall (Advanced WAF)
f5 BIG-IP Domain Name System (DNS)
f5 BIG-IP Advanced Firewall Manager (AFM)
f5 BIG-IP Carrier-Grade NAT (CGNAT)
f5 BIG-IP DDoS Hybrid Defender
f5 BIG-IP SSL Orchestrator
f5 BIG-IP Policy Enforcement Manager (PEM)
f5 BIG-IP Automation Toolchain
Estimated exposure
large≈tens of thousands of BIG-IP systems plausibly in scope (several thousand with the Configuration utility directly internet-exposed per public scans; total… — Estimate based on F5 BIG-IP's very large enterprise and service-provider installed base and public internet scans during the October 2023 BIG-IP exploitation wave showing thousands to tens of thousands of appliances with management/self-IP…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CISA Known Exploited Vulnerability
Affected
F5 BIG-IP Configuration Utility
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
f5
Products
big-ip access policy manager, big-ip advanced firewall manager, big-ip carrier-grade nat, big-ip ddos hybrid defender, big-ip ssl orchestrator, big-ip local traffic manager, big-ip policy enforcement manager, big-ip automation toolchain, big-ip container ingress services, big-ip advanced web application firewall, big-ip domain name system, big-ip application security manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news