Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh2h-7w4m-mhhp

Опубликовано: 05 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 22%
0.00074
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 3.1
nvd
около 1 года назад

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 22%
0.00074
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-345