Insufficient Data Authenticity Verification in BIG-IP APM by F5 Networks
CVE-2025-23415
2.3LOW
What is CVE-2025-23415?
A vulnerability in BIG-IP APM allows attackers to exploit insufficient verification of data authenticity during endpoint inspection, potentially enabling unauthorized bypassing of security checks for VPN connections initiated through the browser network access VPN client on Windows, macOS, and Linux operating systems.
Affected Version(s)
BIG-IP 17.1.0 < 17.1.2
BIG-IP 16.1.0 < 16.1.5
BIG-IP 15.1.0