CVE Vulnerabilities

CVE-2024-28883

Origin Validation Error

Published: May 08, 2024 | Modified: Aug 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An origin validation vulnerability exists in

BIG-IP APM browser network access VPN client

for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 15.1.0 (including) 15.1.10.3 (excluding)
Big-ip_access_policy_manager F5 16.1.0 (including) 16.1.4.2 (excluding)
Big-ip_access_policy_manager F5 17.1.0 (including) 17.1.0 (including)
Big-ip_access_policy_manager_client F5 7.2.3 (including) 7.2.4.4 (excluding)

References