CVE-2023-28742: F5 BIG-IP Domain Name System

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 BIG-IP Domain Name System: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)

Published 2023-05-03. Last modified 2026-06-17.