cbcvebase.
CVE-2023-5450
published 2023-10-10

CVE-2023-5450: An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during…

PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.14%
3.8th percentile
An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

8 ranges
VendorProductVersion rangeFixed in
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager13.1.0 – 13.1.5
f5big-ip_access_policy_manager14.1.0 – 14.1.5
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.1015.1.10
f5big-ip_access_policy_manager>= 16.1.0 < 16.1.416.1.4
f5big-ip_access_policy_manager>= 7.2.3 < 7.2.4.57.2.4.5
f5big-ip_apm
f5big-ip_edge_client>= 7.2.3 < 7.2.4.57.2.4.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.