CVE-2023-46748
F5 BIG-IP Configuration Utility
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVSS
- 8.8
- EPSS
- 4.47% 90.5% percentile
- CISA KEV
- Listed
- Published
- 2023.10.27