CVE-2023-46747

Vulnerability updated 7 months ago (2024-11-29T13:47:03.687Z)
Download STIX
Preview STIX
CVE-2023-46747 is a critical software vulnerability identified in F5 Networks' BIG-IP multi-purpose networking devices/modules. This flaw, an authentication bypass vulnerability, could allow unauthenticated remote code execution (RCE), giving potential attackers the ability to execute arbitrary commands on the affected system. Notably, this is one of three such vulnerabilities that have been discovered in the TMUI portal within the past three years, pointing to a concerning trend. F5 Networks confirmed that CVE-2023-46747, along with another BIG-IP vulnerability (CVE-2023-46748), are being actively exploited by attackers. A public proof-of-concept (PoC) code for the RCE vulnerability is available, which could increase the risk of exploitation. On November 10, 2023, security experts issued alerts about the ongoing exploitation of these vulnerabilities, including another unrelated vulnerability in Citrix (CVE-2023-4966). In response to these threats, F5 Networks has released hotfixes to address the vulnerabilities, including CVE-2023-46747. The company has provided these fixes via their official website, urging users to apply them immediately to mitigate the risk of unauthorized access and potential system compromise. It is crucial for all organizations using affected F5 BIG-IP modules to update their systems promptly to protect against these serious security vulnerabilities.
Description last updated: 2024-03-17T13:16:36.016Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
RCE (Remote ...
CISA
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2023-46747 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CISA
10 months ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
BankInfoSecurity
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago