Nov. 10, 2023, 6:23 p.m. |

FortiGuard Labs | FortiGuard Center - Threat Signal Report fortiguard.fortinet.com

What is the Attack?

The vulnerability allows an unauthenticated attacker to exploit an authentication bypass vulnerability in F5 BIG-IP system. The exploit requires a network access through the management port to execute arbitrary system commands. F5 has warned their customers that threat actors are actively exploiting the vulnerability.

What is the Vendor Solution?


F5 has released relevant firmware updates for the affected products. For more information, visit here.



What FortiGuard Coverage is available?

FortiGuard Labs has an IPS signature "F5.BIG-IP.TMUI.AJP.Smuggling.Authentication.Bypass" …

access a network attack attacker authentication authentication bypass big big-ip bypass bypass vulnerability configuration customers cve cve-2023-46747 exploit exploiting management network network access port solution system threat threat actors unauthenticated utility vendor vulnerability what is

Senior Security Engineer - Detection and Response

@ Fastly, Inc. | US (Remote)

Application Security Engineer

@ Solidigm | Zapopan, Mexico

Defensive Cyber Operations Engineer-Mid

@ ISYS Technologies | Aurora, CO, United States

Manager, Information Security GRC

@ OneTrust | Atlanta, Georgia

Senior Information Security Analyst | IAM

@ EBANX | Curitiba or São Paulo

Senior Information Security Engineer, Cloud Vulnerability Research

@ Google | New York City, USA; New York, USA