A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. 
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-24585 A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 big-ip
F5 big-ip Edge Client
Vendors & Products F5
F5 big-ip
F5 big-ip Edge Client

Wed, 13 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 15:00:00 +0000

Type Values Removed Values Added
Description A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title BIG-IP APM VPN web client for macOS vulnerability
Weaknesses CWE-353
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2025-08-14T03:55:59.425Z

Reserved: 2025-07-29T17:12:25.024Z

Link: CVE-2025-48500

cve-icon Vulnrichment

Updated: 2025-08-13T15:02:52.785Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T15:15:32.533

Modified: 2025-08-13T17:33:46.673

Link: CVE-2025-48500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-13T21:47:01Z