target entity

BIG-IP Configuration Utility

2 source-linked records in the current knowledge graph.

high

CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46747CVE-2023-46748EPSS 96.5%BIG-IP Configuration UtilityF5
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46747: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46747CVE-2023-46748EPSS 96.5%BIG-IP Configuration UtilityF5
CISA KEV ↗ · unattributed attribution