CVE-2025-52585
7.5F5 · BIG-IP
A NULL pointer dereference in the BIG-IP Traffic Management Microkernel can be triggered by specifically crafted requests, causing a service crash when SSL Forward Proxy and ADH ciphers are enabled.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP allows unauthenticated remote attackers to crash the Traffic Management Microkernel via specifically crafted SSL requests.
Vulnerability
The vulnerability is a NULL pointer dereference, categorized as CWE-476, occurring within the Traffic Management Microkernel (TMM) when processing requests in specific SSL configurations. The attack is unauthenticated, as no login is required to send the malformed requests that trigger the crash.
Business impact
Successful exploitation results in the termination of the TMM process, which effectively leads to a denial of service for the affected BIG-IP device. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to network availability and critical traffic management infrastructure. Organizations relying on BIG-IP for load balancing or secure access may face significant downtime if the service is repeatedly crashed by an attacker.
Remediation
Immediate Action: Upgrade to a fixed version, specifically 17.5.0 or later, as recommended by the vendor.
Proactive Monitoring: Monitor system logs for frequent TMM restarts or service crashes that correlate with inbound traffic patterns.
Compensating Controls: If patching is not immediately feasible, disable Anonymous Diffie-Hellman (ADH) ciphers or the SSL Forward Proxy feature on vulnerable virtual servers to mitigate the attack vector.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The potential for unauthenticated denial of service makes this vulnerability a high priority for network administrators. Because the TMM is a core component of the BIG-IP system, its termination disrupts all managed traffic. We strongly recommend scheduling maintenance to apply the vendor-provided updates immediately to restore system stability and prevent potential service disruption.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.