Vulnerability record · CVE-2023-46748 · published 26 October 2023
CVE-2023-46748: F5 BIG-IP Configuration Utility SQL injection leads to command execution
F5 · Big Ip Access Policy Manager
An authenticated SQL injection flaw exists in the BIG-IP Configuration utility. An attacker who already holds valid credentials and can reach the management port or self IP addresses can inject SQL to execute arbitrary system commands on the BIG-IP system. Because BIG-IP devices sit at the network edge and hold sensitive configuration and traffic data, compromise is serious.
Description
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows authenticated remote command execution on edge devices, is in CISA KEV with a short remediation deadline, and has an exploit-tagged reference indicating active exploitation.
What it is
An authenticated SQL injection flaw exists in the BIG-IP Configuration utility. An attacker who already holds valid credentials and can reach the management port or self IP addresses can inject SQL to execute arbitrary system commands on the BIG-IP system. Because BIG-IP devices sit at the network edge and hold sensitive configuration and traffic data, compromise is serious.
Impact
An authenticated attacker gains arbitrary command execution on the BIG-IP appliance, allowing full control of the device, access to its configuration and secrets, and potential lateral movement into the network it protects.
Attack surface
Reached over the network through the BIG-IP management port and/or self IP addresses via the Configuration utility. Authentication is required (PR:L) and no user interaction is needed (UI:N); the vector is AV:N/AC:L.
Exploitation
CVE-2023-46748 is listed in CISA KEV with a due date of 2023-11-21, and a third-party reference is tagged Exploit, indicating active exploitation. EPSS 30-day probability is about 4.5 percent (percentile ~91).
What to do
- Apply the F5 vendor patch per advisory K000137365 as the first action.
- If patching is not immediately possible, restrict access to the BIG-IP Configuration utility management port and self IP addresses to trusted administrative networks only.
- Discontinue use of the product if vendor mitigations are unavailable, per CISA KEV guidance.
- Audit and rotate credentials and secrets stored on or accessible from affected BIG-IP devices.
- Monitor for and remove any unauthorized administrative accounts or configuration changes on BIG-IP systems.
Detection
- Review BIG-IP Configuration utility and audit logs for anomalous SQL-like input or unexpected command execution activity.
- Alert on logins to the management interface from unusual source addresses or outside administrative windows.
- Monitor for unexpected processes, files, or configuration changes on BIG-IP appliances.
- Correlate BIG-IP management access logs with downstream network activity for signs of lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-46748 to the Known Exploited Vulnerabilities catalog on 31 October 2023 as "F5 BIG-IP Configuration Utility SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 November 2023.
Affected products
20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://my.f5.com/manage/s/article/K000137365 | Vendor Advisory |
| https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/ | ExploitThird Party Advisory |
| https://my.f5.com/manage/s/article/K000137365 | Vendor Advisory |
| https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46748 | US Government Resource |
Track CVE-2023-46748 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.