CVE-2020-5892
- EPSS 0.09%
- Published 30.04.2020 22:15:12
- Last modified 21.11.2024 05:34:46
In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.
CVE-2020-5893
- EPSS 0.13%
- Published 30.04.2020 21:15:17
- Last modified 21.11.2024 05:34:46
In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Client responds to authentication requests over HTTP while sending probes for captive portal detection.
CVE-2020-5855
- EPSS 0.15%
- Published 06.02.2020 16:15:12
- Last modified 21.11.2024 05:34:42
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
CVE-2019-6656
- EPSS 0.54%
- Published 25.09.2019 20:15:11
- Last modified 21.11.2024 04:46:53
BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12...
- EPSS 0.12%
- Published 06.12.2018 13:29:00
- Last modified 21.11.2024 03:50:35
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.
CVE-2018-15316
- EPSS 0.14%
- Published 19.10.2018 13:29:00
- Last modified 21.11.2024 03:50:32
In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks.
CVE-2018-5546
- EPSS 0.13%
- Published 17.08.2018 12:29:00
- Last modified 21.11.2024 04:09:02
The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A maliciou...
CVE-2018-5547
- EPSS 0.13%
- Published 17.08.2018 12:29:00
- Last modified 21.11.2024 04:09:02
Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy logon mode which uses a SYSTEM account to establish network access. This feature displays a certificate user interface dialog box wh...