CVE-2025-41430

7.5

F5 · BIG-IP SSL Orchestrator

A vulnerability in F5 BIG-IP SSL Orchestrator allows unauthenticated remote attackers to trigger a denial of service by causing the Traffic Management Microkernel to terminate via specific traffic.

Executive summary

A critical denial of service vulnerability in F5 BIG-IP SSL Orchestrator allows unauthenticated remote attackers to crash the Traffic Management Microkernel, leading to service disruption.

Vulnerability

This issue is caused by improper resource allocation, specifically categorized as CWE-770, where the Traffic Management Microkernel crashes when processing certain traffic. The vulnerability is exploitable by an unauthenticated remote attacker with network access to the BIG-IP system.

Business impact

Successful exploitation results in the termination of the Traffic Management Microkernel, effectively causing a denial of service for all traffic processed by the device. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, as it can disrupt critical network infrastructure and security inspection services provided by the BIG-IP platform.

Remediation

Immediate Action: Administrators must apply the vendor provided security updates as detailed in F5 article K000150667.

Proactive Monitoring: Monitor system logs for unexpected Traffic Management Microkernel restarts or error messages related to resource exhaustion.

Compensating Controls: Implement network access controls to restrict traffic to the BIG-IP management and data planes to authorized sources only, reducing the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the potential for widespread service disruption, immediate patching is strongly recommended. Organizations should verify their current BIG-IP version against the vendor documentation and prioritize the installation of the provided security updates to maintain network stability and availability.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.