F5 BIG-IP vulnerability under active attack after RCE discovery

April 2, 20262 min read1 sources
Share:
F5 BIG-IP vulnerability under active attack after RCE discovery

A critical remote code execution (RCE) vulnerability in F5's BIG-IP networking devices, tracked as CVE-2023-46747, is being actively exploited by threat actors. The flaw, which carries a CVSS severity score of 9.8 out of 10, allows an unauthenticated attacker to execute commands with root privileges, granting them complete control over a compromised system.

The vulnerability resides in the BIG-IP Configuration utility, also known as the Traffic Management User Interface (TMUI). Attackers can exploit the flaw by sending a specially crafted HTTP request to an exposed management port, bypassing authentication entirely. F5 disclosed the vulnerability in late October 2023, and security researchers published proof-of-concept (PoC) exploit code within hours, leading to immediate and widespread attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) quickly added CVE-2023-46747 to its Known Exploited Vulnerabilities (KEV) catalog, confirming the active threat and mandating federal agencies to patch their systems.

A successful attack gives adversaries a powerful foothold inside a target network. BIG-IP devices often sit at critical network junctions, managing application traffic. Compromise can lead to data exfiltration, internal network pivoting, deployment of ransomware, or manipulation of network traffic.

Administrators are strongly urged to apply the security updates provided by F5 immediately. For systems that cannot be patched right away, F5 recommends implementing workarounds that involve restricting access to the TMUI. This includes blocking access from the internet and limiting it to a secure management network, which authorized personnel often access using a VPN.

Share:

// SOURCES

// RELATED

Microsoft begins force-upgrading Windows 11 PCs to unreleased 24H2 version

Microsoft is automatically upgrading some Windows 11 23H2 PCs to the unreleased 24H2 version, raising concerns over stability and user control.

2 min readApr 4

Trump budget proposal signals deep cuts to CISA, raising national security alarms

A past Trump administration budget proposal to slash CISA's funding by hundreds of millions raises alarms about the future of U.S. cyber defense.

6 min readApr 4

Russian money launderer for TrickBot ransomware group sentenced to two years

Denis Dubnikov, a Russian national, has been sentenced for laundering over $400,000 for the notorious TrickBot cybercrime group.

2 min readApr 3

Apple expands iOS 18.7.7 update to block sophisticated DarkSword exploit

Apple has broadened the availability of iOS 18.7.7, patching critical zero-click vulnerabilities exploited by the sophisticated DarkSword surveillance

2 min readApr 3