PT-2023-6486 · F5 · F5 Big-Ip Access Policy Manager+11
CVE-2023-46747
·
Published
2023-10-25
·
Updated
2026-06-25
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 13.1.5 through 17.1.0
Description
An authentication bypass exists in the configuration utility of F5 BIG-IP, including Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Hybrid Defender, Domain Name System, Fraud Protection Service, Link Controller, Local Traffic Manager, Policy Enforcement Manager, and Orchestrator. The issue stems from the failure to protect SQL query structures and the possibility of using alternative paths or channels to circumvent authentication. An unauthenticated attacker with network access to the system via the management port or self IP addresses can exploit this to execute arbitrary system commands. This issue has been actively exploited in real-world incidents.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
SQL injection
Authentication Bypass Using an Alternate Path or Channel
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Big-Ip
F5 Big-Ip Access Policy Manager
F5 Big-Ip Advanced Firewall Manager
F5 Big-Ip Analytics
F5 Big-Ip Application Acceleration Manager
F5 Big-Ip Application Security Manager
F5 Big-Ip Domain Name System
F5 Big-Ip Fraud Protection Service
F5 Big-Ip Hybrid Defender
F5 Big-Ip Link Controller
F5 Big-Ip Local Traffic Manager
F5 Big-Ip Policy Enforcement Manager