← Back to browse · API

CVE-2023-46748

Severity
HIGH
CVSS
8.8
EPSS
0.04468
Risk score
61.76
CISA KEV
Yes
PoC
No
Published
2023-10-26
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-50917, GHSA-9H42-3PGF-QJC8
Products
F5:BIG-IP 13.1.0 <*, F5:BIG-IP 14.1.0 <*, F5:BIG-IP 15.1.0 <*, F5:BIG-IP 16.1.0 <*, F5:BIG-IP 17.1.0 <*, F5:BIG-IP Configuration Utility
Sources
euvd EUVD-2023-50917
cisa.gov CVE-2023-46748

Description

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

References