7.1

CVE-2023-36858

An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Data is provided by the National Vulnerability Database (NVD)
F5Access Policy Manager Clients Version >= 7.2.3 < 7.2.4.3
   ApplemacOS Version-
   MicrosoftWindows Version-
F5Big-ip Access Policy Manager Version >= 13.1.0 <= 13.1.5
   ApplemacOS Version-
   MicrosoftWindows Version-
F5Big-ip Access Policy Manager Version >= 14.1.0 <= 14.1.5
   ApplemacOS Version-
   MicrosoftWindows Version-
F5Big-ip Access Policy Manager Version >= 15.1.0 <= 15.1.9
   ApplemacOS Version-
   MicrosoftWindows Version-
F5Big-ip Access Policy Manager Version >= 16.1.0 <= 16.1.3
   ApplemacOS Version-
   MicrosoftWindows Version-
F5Big-ip Access Policy Manager Version >= 17.0.0 <= 17.1.0
   ApplemacOS Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.222
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
f5sirt@f5.com 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.