CVE Vulnerabilities

CVE-2024-28883

Origin Validation Error

Published: May 08, 2024 | Modified: Aug 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An origin validation vulnerability exists in

BIG-IP APM browser network access VPN client

for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_access_policy_managerF515.1.0 (including)15.1.10.3 (excluding)
Big-ip_access_policy_managerF516.1.0 (including)16.1.4.2 (excluding)
Big-ip_access_policy_managerF517.1.0 (including)17.1.0 (including)
Big-ip_access_policy_manager_clientF57.2.3 (including)7.2.4.4 (excluding)

References