CVE-2023-46747
About
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Rainforest analyst review
A second authentication bypass in F5 BIG-IP, this one reaching the Traffic Management User Interface (TMUI) configuration utility. The Apache front end and the back-end Tomcat service disagree about how to interpret certain requests, so an attacker who can reach the management port or a self IP crafts a request that Apache treats as already authenticated while Tomcat honors it. That request-smuggling-style bypass exposes authenticated endpoints, and chaining it with an SOAP-based AJP call lets the attacker reset admin credentials and run arbitrary system commands as root.
As with the iControl REST bypass, the stakes come from where BIG-IP sits: at the network edge, terminating application traffic and holding the credentials and keys for everything behind it, so root on the appliance is a perimeter breach. Public exploit code followed disclosure within days and mass exploitation began shortly after, so exposed systems should be presumed targeted. The durable control is to keep the management interface and self IPs off any untrusted network entirely; patch to a fixed version, and because the window predates most patching, hunt for unexpected admin resets, new accounts, and command execution on the device.
References
- http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html
- https://my.f5.com/manage/s/article/K000137353
- https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46747
Related CVEs
Frequently asked questions
What is CVE-2023-46747?
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
How severe is CVE-2023-46747?
CVE-2023-46747 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2023-46747 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-46747?
Public advisories list the following as affected: big-ip access policy manager, big-ip advanced firewall manager, big-ip advanced web application firewall, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, +14. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-46747?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
