CVE-2024-28883: BIG-IP APM browser network access VPN client vulnerability
An origin validation vulnerability exists in
BIG-IP APM browser network access VPN client
for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
An origin validation vulnerability exists in the BIG-IP APM browser network access VPN client, which may allow an attacker to bypass F5 endpoint inspection.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28883?
CVE-2024-28883 is classified as a high severity vulnerability due to its ability to potentially bypass endpoint inspection.
How do I fix CVE-2024-28883?
To fix CVE-2024-28883, upgrade to the fixed versions of the BIG-IP APM software as recommended by F5.
What products are affected by CVE-2024-28883?
CVE-2024-28883 affects F5 BIG-IP APM on specified versions including 17.1.0, 16.1.0 to 16.1.4, and 15.1.0 to 15.1.10.
Can CVE-2024-28883 be exploited remotely?
Yes, CVE-2024-28883 can be exploited remotely, allowing attackers to bypass endpoint inspection from various locations.
Is there a workaround for CVE-2024-28883?
F5 currently recommends performing software upgrades to remediate CVE-2024-28883, rather than relying on workarounds.