CVE-2025-23415: BIG-IP APM Endpoint Inspection vulnerability
A missing integrity check vulnerability exists in BIG-IP APM access policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connections initiated through the BIG-IP APM browser network access VPN client for Windows, macOS, and Linux.
Other sources
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23415?
The severity of CVE-2025-23415 is critical due to the potential for attackers to bypass important endpoint inspection checks.
How do I fix CVE-2025-23415?
To fix CVE-2025-23415, upgrade F5 BIG-IP (APM) to versions 17.1.2, 16.1.5, or ensure you are using a version that is not vulnerable.
What systems are affected by CVE-2025-23415?
CVE-2025-23415 affects F5 BIG-IP (APM) versions from 17.1.0 to 17.1.1, 16.1.0 to 16.1.4, and 15.1.0 to 15.1.10.
What type of vulnerability is CVE-2025-23415?
CVE-2025-23415 is classified as a missing integrity check vulnerability.
What are the consequences of exploiting CVE-2025-23415?
Exploiting CVE-2025-23415 may allow an attacker to bypass endpoint inspection, compromising the security of VPN connections.