CVE-2023-46748
CVSS V2 None
CVSS V3 None
Description
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Overview
- CVE ID
- CVE-2023-46748
- Assigner
- f5
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-10-26T20:05:04.967Z
- Last Modified Date
- 2023-11-06T08:17:00.208Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://my.f5.com/manage/s/article/K000137365 | vendor-advisory |
https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-46748 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46748 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 22:34:21 | Added to TrackCVE |