Description
A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Problem types
CWE-353: Missing Support for Integrity Check
Product status
7.2.4 before 7.2.5.3
17.5.0 before *
17.1.0 before *
16.1.0 before *
15.1.0 before *
Credits
F5 acknowledges Adwiteeya Agrawal of Snapchat, Inc for bringing this issue to our attention and following the highest standards of coordinated disclosure.
References
my.f5.com/manage/s/article/K000151782