F5 BIG-IP Critical Vulnerabilities Under Active Exploitation
F5 has issued an urgent security advisory to BIG-IP administrators following the discovery and active exploitation of two significant vulnerabilities. F5 BIG-IP, a suite widely used by large enterprises and government agencies, faces a critical authentication bypass flaw (CVE-2023-46747) and a high-severity SQL injection flaw (CVE-2023-46748).
Despite the availability of security updates, evidence of compromised devices and exploitation in the wild has been observed. The Cybersecurity & Infrastructure Security Agency (CISA) has emphasized the importance of government agencies, in particular, applying these updates by November 21, 2023.
Given the stealthy nature of these exploits, any unpatched BIG-IP endpoints should be considered potentially compromised and administrators are advised to move directly to system cleanup and restoration procedures.
Recommendations
- Immediately apply the latest security updates from F5
- Audit all BIG-IP devices for signs of compromise
- Review access logs for unauthorized activity
- Implement network segmentation for critical infrastructure
- Engage incident response if compromise is suspected
Contact SecureUs Networks for assistance with vulnerability assessment and incident response.