F5 Security Updates – 28 October 2023

F5 has released security updates to fix multiple vulnerabilities across multiple products.

The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, launch SQL injection attacks, execute arbitrary commands, and gain access to the affected products by sending specially crafted requests.

Sample of the addressed vulnerabilities:

1. F5 BIG-IP Command Execution Vulnerability (CVE-2023-46747):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. F5 BIG-IP SQL Injection Vulnerability (CVE-2023-46748):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Data Manipulation

Affected Products:

  • BIG-IP Next (all modules).
  • BIG-IP (all modules).
  • BIG-IP Next SPK.
  • BIG-IP Next CNF.

It should be highlighted that there is no security update for “CVE-2023-46886”, so security administrators should monitor F5 advisory and apply the security patch as soon as it is released.

Vulnerabilities
  • CVE-2023-46747
  • CVE-2023-45886
  • CVE-2023-46748
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

References