CVE-2023-46747
CRITICALUndisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products
big-ip access policy managerf5big-ip advanced firewall managerf5big-ip advanced web application firewallf5big-ip analyticsf5big-ip application acceleration managerf5big-ip application security managerf5Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Undisclosed requests may bypass configuration utility authentication,…
Undisclosed requests may bypass configuration utility authentication,…
Undisclosed requests may bypass configuration utility authentication,…
Undisclosed requests may bypass configuration utility authentication,…
Undisclosed requests may bypass configuration utility authentication,…
Undisclosed requests may bypass configuration utility authentication,…
Frequently Asked Questions
Is CVE-2023-46747 in your stack?
O3 detects CVE-2023-46747 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.