CVE-2025-41430
7.5F5 · BIG-IP SSL Orchestrator
A vulnerability in F5 BIG-IP SSL Orchestrator allows unauthenticated remote attackers to trigger a denial of service by causing the Traffic Management Microkernel to terminate via specific traffic.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP SSL Orchestrator allows unauthenticated remote attackers to crash the Traffic Management Microkernel, leading to service disruption.
Vulnerability
This issue is caused by improper resource allocation, specifically categorized as CWE-770, where the Traffic Management Microkernel crashes when processing certain traffic. The vulnerability is exploitable by an unauthenticated remote attacker with network access to the BIG-IP system.
Business impact
Successful exploitation results in the termination of the Traffic Management Microkernel, effectively causing a denial of service for all traffic processed by the device. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, as it can disrupt critical network infrastructure and security inspection services provided by the BIG-IP platform.
Remediation
Immediate Action: Administrators must apply the vendor provided security updates as detailed in F5 article K000150667.
Proactive Monitoring: Monitor system logs for unexpected Traffic Management Microkernel restarts or error messages related to resource exhaustion.
Compensating Controls: Implement network access controls to restrict traffic to the BIG-IP management and data planes to authorized sources only, reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the potential for widespread service disruption, immediate patching is strongly recommended. Organizations should verify their current BIG-IP version against the vendor documentation and prioritize the installation of the provided security updates to maintain network stability and availability.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.