Main
Vulnerability Database
Exploits
ID:11208 - Exploit for Authentication bypass using an alternate path or channel in BIG-IP and BIG-IQ Centralized Management - CVE-2023-46747
ID:11208 - Exploit for Authentication bypass using an alternate path or channel in BIG-IP and BIG-IQ Centralized Management - CVE-2023-46747
Published: March 14, 2025
Vulnerability identifier: #VU82544
Vulnerability risk: High
CVE-ID: CVE-2023-46747
CWE-ID: CWE-288
Exploitation vector: Remote access
Vulnerable software:
BIG-IP
BIG-IQ Centralized Management
BIG-IP
BIG-IQ Centralized Management
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authentication in the Configuration utility. A remote non-authenticated attacker can send a specially crafted requests to the system, bypass authentication and execute arbitrary commands on the device.
Remediation
Install updates from vendor's website.