K000138744 : BIG-IP APM browser network access VPN client vulnerability CVE-2024-28883
Discription

Security Advisory Description An origin validation vulnerability exists in the BIG-IP APM browser network access VPN client, which may allow an attacker to bypass F5 endpoint inspection. (CVE-2024-28883) Impact A remote unauthenticated attacker with a man-in-the-middle (MITM) position may exploit this vulnerability and establish a network access (VPN) connection with a BIG-IP APM system. This vulnerability specifically affects the BIG-IP APM browser network access VPN client when the BIG-IP APM access policy is configured with an endpoint inspection item in the Visual Policy Editor (VPE), Endpoint Security (client or server). BIG-IP Edge Client/F5 Access/CLI and other clients are not…Read More

Back to Main

Subscribe for the latest news: