Vulnerability threat dossier

CVE-2023-46747

f5big-ip access policy manager

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

VTP deterministic threat61.3of 100 · CVSS excluded

VTP analyst assessment

F5 BIG-IP Configuration Utility authentication bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2023-46747 can bypass BIG-IP Configuration Utility authentication and execute arbitrary system commands. The attacker needs network access through the management port or self IP addresses. ENISA lists the vulnerability as known exploited, and CISA KEV records known ransomware use.

Why it matters

  • Management ports and self IP addresses can expose administrative functions to reachable networks.
  • Successful command execution could allow an attacker to control functions on the affected BIG-IP system.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied Fortinet incident reporting does not concern F5 BIG-IP and provides no campaign evidence for this CVE.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected F5 BIG-IP versions, apply F5's remediation for CVE-2023-46747.

AI baseline history (3)
  1. BASELINE ASSESSED
    F5 BIG-IP Configuration Utility authentication bypassgpt-5.6-terra · low
  2. BASELINE ASSESSED
    F5 BIG-IP configuration utility authentication bypassgpt-5.6-sol · high
  3. BASELINE ASSESSED
    F5 BIG-IP authentication bypassgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.97100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.97; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2023-46747ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0031 Oct
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  2. 00:0031 Oct
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

Thai Broadband Provider Hacked via Fortinet Vulnerability

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek .

CVE-2018-13379CVE-2021-22986CVE-2022-1388CVE-2022-42475CVE-2023-27997CVE-2023-46747CVE-2024-21762
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2023-46747

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2023-46747
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.3vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.3 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-288, CWE-306
CPE records
20
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.