CVE-2023-43124: F5 BIG-IP Access Policy Manager

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected products

  • F5 BIG-IP Access Policy Manager: from 14.1.5.2, up to and including 14.1.5.6; from 15.1.8, up to and including 15.1.10; from 16.1.3.3, up to and including 16.1.4; version 13.1.5.1 only; version 17.1.0 only
  • F5 BIG-IP Access Policy Manager Client: from 7.2.3, up to and including 7.2.4

Published 2023-09-27. Last modified 2026-06-17.