← Vulnerability feed

Vulnerability record · CVE-2023-46748 · published 26 October 2023

CVE-2023-46748: F5 BIG-IP Configuration Utility SQL injection leads to command execution

F5 · Big Ip Access Policy Manager

An authenticated SQL injection flaw exists in the BIG-IP Configuration utility. An attacker who already holds valid credentials and can reach the management port or self IP addresses can inject SQL to execute arbitrary system commands on the BIG-IP system. Because BIG-IP devices sit at the network edge and hold sensitive configuration and traffic data, compromise is serious.

8.8 CVSS 3.1 High CISA KEV since 31 Oct 2023 EPSS 4.5% · top 8.9% CWE-89 · SQL injection
8.8CVSS 3.1 base score
4.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
20Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows authenticated remote command execution on edge devices, is in CISA KEV with a short remediation deadline, and has an exploit-tagged reference indicating active exploitation.

What it is

An authenticated SQL injection flaw exists in the BIG-IP Configuration utility. An attacker who already holds valid credentials and can reach the management port or self IP addresses can inject SQL to execute arbitrary system commands on the BIG-IP system. Because BIG-IP devices sit at the network edge and hold sensitive configuration and traffic data, compromise is serious.

Impact

An authenticated attacker gains arbitrary command execution on the BIG-IP appliance, allowing full control of the device, access to its configuration and secrets, and potential lateral movement into the network it protects.

Attack surface

Reached over the network through the BIG-IP management port and/or self IP addresses via the Configuration utility. Authentication is required (PR:L) and no user interaction is needed (UI:N); the vector is AV:N/AC:L.

Exploitation

CVE-2023-46748 is listed in CISA KEV with a due date of 2023-11-21, and a third-party reference is tagged Exploit, indicating active exploitation. EPSS 30-day probability is about 4.5 percent (percentile ~91).

What to do

  • Apply the F5 vendor patch per advisory K000137365 as the first action.
  • If patching is not immediately possible, restrict access to the BIG-IP Configuration utility management port and self IP addresses to trusted administrative networks only.
  • Discontinue use of the product if vendor mitigations are unavailable, per CISA KEV guidance.
  • Audit and rotate credentials and secrets stored on or accessible from affected BIG-IP devices.
  • Monitor for and remove any unauthorized administrative accounts or configuration changes on BIG-IP systems.

Detection

  • Review BIG-IP Configuration utility and audit logs for anomalous SQL-like input or unexpected command execution activity.
  • Alert on logins to the management interface from unusual source addresses or outside administrative windows.
  • Monitor for unexpected processes, files, or configuration changes on BIG-IP appliances.
  • Correlate BIG-IP management access logs with downstream network activity for signs of lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-46748 to the Known Exploited Vulnerabilities catalog on 31 October 2023 as "F5 BIG-IP Configuration Utility SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 November 2023.

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46748 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.3CVE-2026-94127F5 big-ip access policy manager heap-based buffer overflow vulnerabilityWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution…KEVEPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2023-46748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.