F5 has identified a critical security vulnerability affecting the BIG-IP system’s Configuration utility, which allows an unauthenticated attacker with network access to execute arbitrary system commands. This vulnerability is tracked as CVE-2023-46747 and has been rated with a CVSS score of 9.8 out of 10. Importantly, this issue pertains to the control plane only, with no exposure to the data plane.
The following versions of BIG-IP are vulnerable:
F5 provides a mitigation script for BIG-IP versions 14.1.0 and later. The script should be applied with caution, as it can have specific considerations:
The script will mitigate the issue and restart the necessary services. Detailed guidance and the script can be found from here: https://my.f5.com/manage/s/article/K000137353 .
Until you can install a fixed version or apply the mitigation script, you can use the following temporary mitigations:
You can block all access to the Configuration utility using self IP addresses by changing the Port Lockdown setting to “Allow None” for each self IP address on the system. If you need to open any ports, use the “Allow Custom” option while ensuring that access to the Configuration utility is blocked. This action prevents all access to the Configuration utility and may impact other services, including high availability configurations.
To mitigate the vulnerability, restrict management access to BIG-IP products to trusted users and devices over a secure network. Refer to F5’s documentation for detailed information on securing access to BIG-IP systems.