CVE-2023-22372: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 BIG-IP Access Policy Manager: from 7.2.2, before 7.2.4.1 (fixed in 7.2.4.1); from 13.1.0, up to and including 13.1.5; from 14.1.0, up to and including 14.1.5; from 15.1.0, up to and including 15.1.8; from 16.1.0, up to and including 16.1.3; from 17.0.0, up to and including 17.1.0

Published 2023-05-03. Last modified 2026-06-17.