SB2025020735 - Security restrictions bypass in BIG-IP APM endpoint inspection
Published: February 7, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing support for integrity check (CVE-ID: CVE-2025-23415)
The vulnerability allows a remote user to bypass implemented security checks.
The vulnerability exists due to a missing integrity check in BIG-IP APM access policy endpoint inspection. A remote user can bypass endpoint inspection checks for VPN connections initiated through the BIG-IP APM browser network access VPN client for Windows, macOS, and Linux.
Remediation
Install update from vendor's website.