CVE Vulnerabilities

CVE-2025-48500

Missing Support for Integrity Check

Published: Aug 13, 2025 | Modified: Oct 21, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 15.1.0 (including) 15.1.10.8 (excluding)
Big-ip_access_policy_manager F5 16.1.0 (including) 16.1.6.1 (excluding)
Big-ip_access_policy_manager F5 17.1.0 (including) 17.1.3 (excluding)
Big-ip_access_policy_manager F5 17.5.0 (including) 17.5.1.3 (excluding)
Big-ip_access_policy_manager_client F5 7.2.5 (including) 7.2.5 (including)

Potential Mitigations

References