ID:12194 - Exploit for Authentication bypass using an alternate path or channel in BIG-IP and BIG-IQ Centralized Management - CVE-2023-46747

 
Main Vulnerability Database Exploits ID:12194 - Exploit for Authentication bypass using an alternate path or channel in BIG-IP and BIG-IQ Centralized Management - CVE-2023-46747

ID:12194 - Exploit for Authentication bypass using an alternate path or channel in BIG-IP and BIG-IQ Centralized Management - CVE-2023-46747

Published: December 12, 2025


Vulnerability identifier: #VU82544
Vulnerability risk: High
CVE-ID: CVE-2023-46747
CWE-ID: CWE-288
Exploitation vector: Remote access
Vulnerable software:
BIG-IP
BIG-IQ Centralized Management

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper authentication in the Configuration utility. A remote non-authenticated attacker can send a specially crafted requests to the system, bypass authentication and execute arbitrary commands on the device.


Remediation

Install updates from vendor's website.