← Back to browse · API

CVE-2023-46747

Severity
CRITICAL
CVSS
9.8
EPSS
0.96515
Risk score
58.78
CISA KEV
Yes
PoC
No
Published
2023-10-26
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-50916, GHSA-PQ6P-FC96-WC5W
Products
F5:BIG-IP 13.1.0 <*, F5:BIG-IP 14.1.0 <*, F5:BIG-IP 15.1.0 <*, F5:BIG-IP 16.1.0 <*, F5:BIG-IP 17.1.0 <*, F5:BIG-IP Configuration Utility
Sources
cisa.gov CVE-2023-46747
euvd EUVD-2023-50916

Description

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

References