CVE-2025-53856
7.5F5 · BIG-IP
A vulnerability in F5 BIG-IP systems with ePVA enabled allows unauthenticated attackers to cause a Traffic Management Microkernel (TMM) termination, resulting in a denial-of-service condition.
Executive summary
A critical denial-of-service vulnerability in F5 BIG-IP allows unauthenticated attackers to crash the Traffic Management Microkernel via specifically crafted network traffic.
Vulnerability
The flaw, categorized as CWE-705, involves incorrect control flow scoping within the embedded Packet Velocity Acceleration (ePVA) feature. An unauthenticated remote attacker can trigger this condition by sending undisclosed traffic to virtual servers, NAT, or SNAT objects, causing the TMM process to terminate.
Business impact
Successful exploitation results in a complete denial of service for the affected BIG-IP device, which typically serves as a critical gateway for application delivery and security. Given the CVSS score of 7.5 and the high availability requirements of these appliances, the business impact includes significant service interruption, loss of connectivity for backend applications, and potential disruption to user traffic flows.
Remediation
Immediate Action: Upgrade affected BIG-IP systems to the patched versions provided in the vendor advisory (K000156707) as soon as possible.
Proactive Monitoring: Monitor device logs for TMM process restarts or unexpected service crashes that may indicate exploitation attempts.
Compensating Controls: Review hardware configurations to determine if ePVA is enabled, and consider disabling the feature as a temporary workaround if an immediate upgrade is not feasible.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing F5 BIG-IP infrastructure must prioritize this update to maintain service availability. Given that this vulnerability allows for unauthenticated disruption of critical network services, testing and deploying the vendor-supplied patches should be scheduled during the next maintenance window to prevent potential denial-of-service attacks.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.