LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 31, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 21, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-46748 to its Known Exploited Vulnerabilities catalog on Oct 31, 2023, with a federal patch deadline of Nov 21, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to…

CVE-2023-46748 is an SQL injection vulnerability in the F5 BIG-IP Configuration Utility. An authenticated attacker who can reach the device over the network through the BIG-IP management port or self IP addresses may be able to execute system commands. The issue can be combined with CVE-2023-46747. Because BIG-IP appliances often sit at critical points in network traffic paths, successful abuse can give an attacker a foothold for further control of the device and the services it protects. Confirm all version and configuration details against the vendor advisory.

How it works

The underlying weakness is CWE-89, improper neutralization of special elements used in an SQL command. In the Configuration Utility, user-controlled input that reaches a database query is not adequately sanitized. An attacker who already has valid credentials and network access to the management interface can craft input that alters the intended SQL statement. According to the CISA summary, this can result in the ability to execute system commands on the device. The vulnerability does not require unauthenticated access, but once authentication and network reachability are present, the injection path can be abused. Exact request formats, parameters, or payloads are not described here; treat any public proof-of-concept material with caution and validate findings only against official vendor guidance.

Am I affected? How to find it in your systems

F5 BIG-IP devices commonly appear as load balancers, application delivery controllers, or security gateways in data centers and cloud environments. The Configuration Utility is the web-based management interface used by administrators. Inventory every BIG-IP instance by querying asset-management systems, network discovery tools, or F5-specific management platforms for devices that expose the management port or self IP addresses. Review which versions of the software are running and compare them to the fixed releases listed in the vendor advisory; do not rely on version ranges stated elsewhere. Check whether the management interface is reachable from untrusted networks or from segments that contain lower-privilege accounts. Look for anomalous authentication events, unexpected SQL-related errors in utility logs, or command-execution artifacts that appear after legitimate administrative sessions. Telemetry from network sensors that monitor traffic to management ports can also surface unusual query patterns consistent with injection attempts.

How to remediate

Apply the vendor-supplied update that addresses CVE-2023-46748 as soon as operational testing permits. Follow the exact installation and reboot procedures given in the F5 advisory. After patching, re-verify that the Configuration Utility is no longer vulnerable by confirming the installed software level. As secondary hardening for this class of flaw, restrict administrative access to the management port and self IP addresses with network ACLs or firewall rules so that only trusted jump hosts or management networks can reach them. Enforce strong authentication, including multi-factor methods where supported, and ensure that accounts used for the utility have the least privileges necessary. Regularly review and rotate credentials, and keep the device’s configuration backups offline and integrity-checked.

If you can't patch immediately

Until the update can be installed, reduce the attack surface by isolating the management interface. Place the management port and self IP addresses behind strict network segmentation so that only a small set of authorized administrative systems can connect. If a web application firewall or reverse proxy sits in front of the utility, enable rules that detect and block common SQL injection patterns; treat this as a temporary virtual patch and re-evaluate after the real fix is applied. Disable any non-essential features of the Configuration Utility that are not required for day-to-day operations. Increase monitoring of authentication logs, process creation events, and outbound connections from the BIG-IP device so that anomalous activity can be investigated quickly. If mitigations cannot be implemented, CISA advises discontinuing use of the product until a secure configuration is possible.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to device compromise and subsequent data exposure. Review logs for signs of unauthorized command execution or configuration changes, and treat any confirmed intrusion as a potential breach that requires full incident response. Known ransomware use of this specific CVE is not documented. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedF5 · BIG-IP Configuration Utility
WeaknessCWE-89
Added to CISA KEVOct 31, 2023
Federal patch deadlineNov 21, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities