First published: Wed Aug 02 2023(Updated: )
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Access Policy Manager Clients | >=7.2.3<7.2.4.3 | |
F5 Big-ip Access Policy Manager | >=13.1.0<=13.1.5 | |
F5 Big-ip Access Policy Manager | >=14.1.0<=14.1.5 | |
F5 Big-ip Access Policy Manager | >=15.1.0<=15.1.9 | |
F5 Big-ip Access Policy Manager | >=16.1.0<=16.1.3 | |
F5 Big-ip Access Policy Manager | >=17.0.0<=17.1.0 | |
F5 BIG-IP APM | >=17.0.0<=17.1.0=3 | 17.1.1 |
F5 BIG-IP APM | >=16.1.0<=16.1.3=3 | 16.1.4 |
F5 BIG-IP APM | >=15.1.0<=15.1.10=3 | |
F5 BIG-IP APM | >=14.1.0<=14.1.5=3 | |
F5 BIG-IP APM | >=13.1.0<=13.1.5 | |
F5 APM Clients | =7.2.3 | 7.2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38418 is a vulnerability in the BIG-IP Edge Client Installer on macOS that does not follow best practices for elevating privileges during the installation process.
Affected software versions include F5 Access Policy Manager Clients 7.2.3 to 7.2.4.3, F5 Big-ip Access Policy Manager 13.1.0 to 13.1.5, F5 Big-ip Access Policy Manager 14.1.0 to 14.1.5, F5 Big-ip Access Policy Manager 15.1.0 to 15.1.9, F5 Big-ip Access Policy Manager 16.1.0 to 16.1.3, and F5 Big-ip Access Policy Manager 17.0.0 to 17.1.0.
CVE-2023-38418 has a severity rating of 7.8 (high).
To fix CVE-2023-38418, upgrade to a version of the software that has addressed the vulnerability.
You can find more information about CVE-2023-38418 at the following reference link: [link](https://my.f5.com/manage/s/article/K000134746).