CVE-2023-46748
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
HIGH · CVSS 8.8
⚠ CISA KEV
EPSS 0.04348
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0