CVE-2025-48500

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
13/08/2025
Last modified:
21/10/2025

Description

A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. <br /> Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 15.1.0 (including) 15.1.10.8 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.6.1 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 17.1.0 (including) 17.1.3 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 17.5.0 (including) 17.5.1.3 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager_client:7.2.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools