cbcvebase.
CVE-2023-46747
published 2023-10-26

CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-11-21
Exploited in the wild
EPSS
96.52%
99.9th percentile
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected

125 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip>= 13.1.0 < **
f5big-ip>= 14.1.0 < **
f5big-ip>= 15.1.0 < **
f5big-ip>= 16.1.0 < **
f5big-ip>= 17.1.0 < **
f5big-ip_aam
f5big-ip_access_policy_manager13.1.0 – 13.1.5
f5big-ip_access_policy_manager14.1.0 – 14.1.5
f5big-ip_access_policy_manager15.1.0 – 15.1.10
f5big-ip_access_policy_manager16.1.0 – 16.1.4
f5big-ip_access_policy_manager17.1.0 – 17.1.1
f5big-ip_advanced_firewall_manager13.1.0 – 13.1.5
f5big-ip_advanced_firewall_manager14.1.0 – 14.1.5
f5big-ip_advanced_firewall_manager15.1.0 – 15.1.10
f5big-ip_advanced_firewall_manager16.1.0 – 16.1.4
f5big-ip_advanced_firewall_manager17.1.0 – 17.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall13.1.0 – 13.1.5
f5big-ip_advanced_web_application_firewall14.1.0 – 14.1.5
f5big-ip_advanced_web_application_firewall15.1.0 – 15.1.10
f5big-ip_advanced_web_application_firewall16.1.0 – 16.1.4
f5big-ip_advanced_web_application_firewall17.1.0 – 17.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics13.1.0 – 13.1.5

Detection & IOCsextracted from sources · hover to see the quote

path/var/log/tomcat/catalina.out
otherjava.sql.SQLException: Column not found: 0. {...) sh: no job control in this shell sh-4.2$ sh-4.2$ exit
  • CVE-2023-46747 is an authentication bypass in the BIG-IP Configuration utility (TMUI) exploitable via the management port and/or self IP addresses without authentication; attackers chained it with CVE-2023-46748 (SQL injection) to execute arbitrary system commands.
  • F5 observed threat actors using CVE-2023-46747 and CVE-2023-46748 in combination; applying the mitigation for CVE-2023-46747 is sufficient to stop most chained attacks.
  • Attackers actively erase forensic traces on compromised BIG-IP devices; absence of IOCs does not confirm a clean system — treat unpatched devices as compromised.
  • CVE-2023-46747 post-exploitation has been associated with the Supershell C2 framework (reverse SSH shell over web services); look for outbound SSH-over-HTTP/HTTPS connections from BIG-IP management interfaces.
  • Monitor BIG-IP logs for SQL injection artefacts in /var/log/tomcat/catalina.out indicating chained exploitation: look for 'Column not found: 0' followed by shell spawn strings 'sh: no job control in this shell'.
  • ·CVE-2023-46747 is exploitable via the management port AND/OR self IP addresses; restricting access to the Configuration utility from both vectors is required to reduce attack surface.
  • ·Not all exploited BIG-IP systems will display the same IOCs; a skilled attacker may remove all traces, so absence of evidence is not evidence of absence of compromise.
  • ·Software versions that have reached End of Technical Support (EoTS) are not evaluated for CVE-2023-46747; organizations on EoTS versions have no vendor-provided fix path.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.