By Interestana AI Editorial — AI-drafted, human-overseen. How we report
F5 Patches BIG-IP APM Zero-Day Exploited in RCE Attacks
F5 Networks has issued security advisories and released patches to address a critical zero-day vulnerability affecting its BIG-IP Application Security Manager (APM) product. This vulnerability, identified as CVE-2023-46747, has been actively exploited in the wild, allowing attackers to achieve remote code execution (RCE) on vulnerable systems. The flaw specifically impacts the BIG-IP APM component, which is used for access management and secure remote access to applications and network resources.
The exploitation of this zero-day vulnerability means that attackers could gain unauthorized control over systems protected by BIG-IP APM, potentially leading to data breaches, system compromise, or further network infiltration. F5 has confirmed that the vulnerability is being actively exploited, underscoring the urgency for users to apply the provided patches. The company has not disclosed the exact number of affected customers or the specific nature of the exploits observed, but the severity of RCE vulnerabilities typically indicates a high risk.
To mitigate the risk, F5 is urging all users of BIG-IP APM to upgrade to fixed versions of the software. The company has provided specific version numbers for the patched releases on its support website. Users are advised to consult the F5 security bulletin for detailed information on affected versions and the corresponding fixes. The BIG-IP platform is a widely used application delivery controller (ADC) that provides a range of services, including load balancing, web application firewalling, and secure access, making a vulnerability in its APM module a significant concern for many organizations.
This incident highlights the ongoing threat posed by zero-day exploits, which are vulnerabilities that are unknown to the vendor and for which no patches are available at the time of initial exploitation. The active exploitation of CVE-2023-46747 suggests that threat actors may have discovered this flaw independently and are leveraging it before F5 could develop and distribute a fix. Organizations relying on F5 BIG-IP APM are strongly encouraged to prioritize the application of these security updates to protect their infrastructure and sensitive data from potential compromise. The company's proactive release of patches following the discovery of active exploitation demonstrates a commitment to addressing critical security issues, but the initial period of exploitation leaves a window of vulnerability. Further details regarding the technical aspects of the vulnerability and the exploitation methods are expected to be released by security researchers and F5 in the coming days, providing more context for defenders.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.