CVE-2025-48500: BIG-IP APM VPN web client for macOS vulnerability
A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
A missing file integrity check vulnerability exists on the macOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48500?
CVE-2025-48500 has a critical severity rating due to the potential for local, authenticated attackers to install malicious software.
How do I fix CVE-2025-48500?
To remediate CVE-2025-48500, it is recommended to upgrade to patched versions of F5 BIG-IP (APM) and APM Clients as specified in the vendor's advisory.
What versions are affected by CVE-2025-48500?
CVE-2025-48500 affects F5 BIG-IP (APM) versions 17.5.0 to 17.5.1, 17.1.0 to 17.1.2, and 16.1.0 to 16.1.6, along with APM Clients version 7.2.5.
Who can exploit CVE-2025-48500?
CVE-2025-48500 can be exploited by local, authenticated attackers who have access to the local file system.
What impact does CVE-2025-48500 have on systems?
The impact of CVE-2025-48500 includes the potential for exploitation through the replacement of the legitimate F5 VPN client installer with a malicious package.