CVE-2023-22283: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 BIG-IP Access Policy Manager: from 7.2.2, before 7.2.3.1 (fixed in 7.2.3.1); from 13.1.0, up to and including 13.1.5; from 14.1.0, up to and including 14.1.5; from 15.1.0, up to and including 15.1.8; from 16.1.0, up to and including 16.1.3; from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Edge: affected versions not specified
Published 2023-02-01. Last modified 2026-06-17.