QID 378976

Date Published: 2023-10-27

QID 378976: F5 BIG-IP Unauthenticated Remote Code Execution (RCE) Vulnerability (K000137353,K000137365)

CVE-2023-46747: F5 BIG-IP is vulnerable to remote code execution vulnerability. The vulnerability may allow a remote attacker to bypass configuration utility authentication.

CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility. This vulnerability may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. There is no data plane exposure; this is a control plane issue only.

Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.0 - 16.1.4
F5 BIG-IP version 15.1.0 - 15.1.10
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

Successful exploitation of the vulnerability may allow a remote attacker to bypass authentication and execute arbitrary commands remotely.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendor has released patch addressing the vulnerability. For more information, please refer to K000137353, K000137365

    CVEs related to QID 378976

    Software Advisories
    Advisory ID Software Component Link
    K000137353 URL Logo my.f5.com/manage/s/article/K000137353
    K000137365 URL Logo my.f5.com/manage/s/article/K000137365