PT-2023-6486 · F5 · F5 Big-Ip Access Policy Manager+11

CVE-2023-46747

·

Published

2023-10-25

·

Updated

2026-06-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 13.1.5 through 17.1.0
Description An authentication bypass exists in the configuration utility of F5 BIG-IP, including Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Hybrid Defender, Domain Name System, Fraud Protection Service, Link Controller, Local Traffic Manager, Policy Enforcement Manager, and Orchestrator. The issue stems from the failure to protect SQL query structures and the possibility of using alternative paths or channels to circumvent authentication. An unauthenticated attacker with network access to the system via the management port or self IP addresses can exploit this to execute arbitrary system commands. This issue has been actively exploited in real-world incidents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

SQL injection

Authentication Bypass Using an Alternate Path or Channel

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07232
BDU:2023-07400
CVE-2023-46747

Affected Products

F5 Big-Ip
F5 Big-Ip Access Policy Manager
F5 Big-Ip Advanced Firewall Manager
F5 Big-Ip Analytics
F5 Big-Ip Application Acceleration Manager
F5 Big-Ip Application Security Manager
F5 Big-Ip Domain Name System
F5 Big-Ip Fraud Protection Service
F5 Big-Ip Hybrid Defender
F5 Big-Ip Link Controller
F5 Big-Ip Local Traffic Manager
F5 Big-Ip Policy Enforcement Manager