7.8
CVE-2023-38418
- EPSS 0.06%
- Published 02.08.2023 16:15:10
- Last modified 21.11.2024 08:13:31
- Source f5sirt@f5.com
- Teams watchlist Login
- Open Login
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Data is provided by the National Vulnerability Database (NVD)
F5 ≫ Access Policy Manager Clients Version >= 7.2.3 < 7.2.4.3
F5 ≫ Big-ip Access Policy Manager Version >= 13.1.0 <= 13.1.5
F5 ≫ Big-ip Access Policy Manager Version >= 14.1.0 <= 14.1.5
F5 ≫ Big-ip Access Policy Manager Version >= 15.1.0 <= 15.1.9
F5 ≫ Big-ip Access Policy Manager Version >= 16.1.0 <= 16.1.3
F5 ≫ Big-ip Access Policy Manager Version >= 17.0.0 <= 17.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.175 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
f5sirt@f5.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.