CVE-2023-46748
published 2023-10-26CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the…
PriorityP184high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-11-21
Exploited in the wild
EPSS
4.47%
90.4th percentile
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 13.1.0 < * | * |
| f5 | big-ip | >= 14.1.0 < * | * |
| f5 | big-ip | >= 15.1.0 < * | * |
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < * | * |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.4 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 – 16.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.1 | — |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_advanced_web_application_firewall | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_advanced_web_application_firewall | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 – 16.1.4 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.1 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
otherjava.sql.SQLException: Column not found: 0. {...) sh: no job control in this shell sh-4.2$ sh-4.2$ exit↗
- →Look for SQL injection exploitation evidence in the Tomcat log file /var/log/tomcat/catalina.out; the specific pattern includes a SQLException followed by shell spawn indicators ('sh: no job control in this shell', 'sh-4.2$'), confirming arbitrary OS command execution via the SQL injection. ↗
- →CVE-2023-46748 is actively chained with CVE-2023-46747 (auth bypass, CVSS 9.8); detecting exploitation of either vulnerability should trigger investigation for both, as threat actors use them in combination. ↗
- →Attackers actively erase forensic traces on compromised BIG-IP devices; absence of log evidence does NOT confirm a clean system — treat any unpatched, exposed BIG-IP as potentially compromised. ↗
- →Monitor network access to the BIG-IP Configuration utility via the management port and self IP addresses for authenticated sessions performing unusual or unexpected requests, as the attack vector requires network access through these interfaces. ↗
- ·Not all exploited systems will exhibit the same IoCs; a skilled attacker may remove all traces of compromise, making log-based detection unreliable as a sole indicator. ↗
- ·Software versions that have reached End of Technical Support (EoTS) are not evaluated for this CVE; detections should account for the fact that EoTS devices may be vulnerable but are not covered by vendor advisories. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
cisa·2023-10-31·CVSS 9.8
CVE-2023-46747 [CRITICAL] CWE-288 F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
Vulnerability: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
Affected: F5 BIG-IP Configuration Utility
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://my.f5.com/manage/s/article/K000137353; https://nvd.nist.gov/vuln/detail/CVE-2023-46747
Remediation Due Date: 2023-11-21
CISA
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
cisa·2023-10-31·CVSS 9.8
CVE-2023-46748 [CRITICAL] CWE-89 F5 BIG-IP Configuration Utility SQL Injection Vulnerability
Vulnerability: F5 BIG-IP Configuration Utility SQL Injection Vulnerability
Affected: F5 BIG-IP Configuration Utility
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://my.f5.com/manage/s/article/K000137365 ; https://nvd.nist.gov/vuln/detail/CVE-2023-46748
Remediation Due Date: 2023-11-21
F5
CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenti...
vendor_f5·2023-10-26·CVSS 8.8
CVE-2023-46748 [HIGH] CWE-89 CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenti...
CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenti...
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, Big-Ip Automation Tool
GHSA
GHSA-9h42-3pgf-qjc8: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access
ghsa_unreviewed·2023-10-26
CVE-2023-46748 [HIGH] CWE-89 GHSA-9h42-3pgf-qjc8: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
VulnCheck
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-46748 [CRITICAL] CWE-89 F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
Affected: F5 BIG-IP Configuration Utility
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://my.f5.com/manage/s/article/K000137353; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cyble.com/blog/active-exploitation-of-big-ip-and-citrix-vulnerabilities-observed-by-cyble-global-sensor-intelligence
VulnCheck
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-46747 [CRITICAL] CWE-288 F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.
Affected: F5 BIG-IP Configuration Utility
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cyble.com/blog/active-exploita
No detection rules found.
No public exploits indexed.
Qualys
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
blogs_qualys·2025-10-18
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
## Table of Contents
CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscores the S
Qualys
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
blogs_qualys·2025-10-18
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
#### Table of Contents
- CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
- The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
- How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
- Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscore
Tenable
CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
blogs_tenable·2024-05-09·CVSS 7.5
[HIGH] CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
New BIG-IP Next Central Manager bugs allow device takeover
blogs_bleepingcomputer·2024-05-08·CVSS 7.5
CVE-2024-26026 [HIGH] New BIG-IP Next Central Manager bugs allow device takeover
## New BIG-IP Next Central Manager bugs allow device takeover
## Sergiu Gatlan
F5 has fixed two high-severity BIG-IP Next Central Manager vulnerabilities, which can be exploited to gain admin control and create hidden rogue accounts on any managed assets.
Next Central Manager allows administrators to control on-premises or cloud BIG-IP Next instances and services via a unified management user interface.
The flaws are an SQL injection vulnerability ( CVE-2024-26026 ) and an OData injection vulnerability ( CVE-2024-21793 ) found in the BIG-IP Next Central Manager API that would allow unauthenticated attackers to execute malicious SQL statements on unpatched devices remotely.
SQL injection attacks involve injecting malicious SQL queries into input fields or parameters in database queries
Bleepingcomputer
Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
blogs_bleepingcomputer·2023-11-01·CVSS 9.8
[CRITICAL] Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
## Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
## Bill Toulas
F5 is warning BIG-IP admins that devices are being breached by "skilled" hackers exploiting two recently disclosed vulnerabilities to erase signs of their access and achieve stealthy code execution.
F5 BIG-IP is a suite of products and services offering load balancing, security, and performance management for networked applications. The platform has been widely adopted by large enterprises and government organizations, making any flaws in the product a significant concern.
Last week, F5 urged admins to apply available security updates for two newly discovered vulnerabilities:
CVE-2023-46747 – Critical (CVSS v3.1 score: 9.8) authentication bypass flaw allowing an attacker to access the Configuration utility an
Tenable
CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
blogs_tenable·2023-10-27·CVSS 9.8
[CRITICAL] CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://my.f5.com/manage/s/article/K000137365https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/https://my.f5.com/manage/s/article/K000137365https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46748
2023-10-26
Published
2023-10-31
Added to CISA KEV
Exploited in the wild