CVE-2025-54854
7.5F5 · BIG-IP
An out-of-bounds read vulnerability in F5 BIG-IP APM allows unauthenticated attackers to cause a denial-of-service condition by sending specially crafted traffic to an OAuth-configured virtual server.
Executive summary
A critical denial-of-service vulnerability in F5 BIG-IP systems, caused by an out-of-bounds read in the apmd process, poses a significant risk to service availability.
Vulnerability
The vulnerability is an out-of-bounds read (CWE-125) occurring within the apmd process when an OAuth access profile is active. It is exploitable by unauthenticated remote attackers who can trigger a process termination by sending crafted traffic to the affected virtual server.
Business impact
Successful exploitation results in the termination of the apmd process, leading to a denial-of-service for the affected BIG-IP modules. Given the CVSS score of 7.5, this vulnerability represents a high-severity risk to business continuity, as it can disrupt critical access management services and prevent legitimate users from authenticating or accessing protected resources.
Remediation
Immediate Action: Update the affected F5 BIG-IP systems to the specified fixed versions (e.g., 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8) as detailed in the F5 security advisory K000156602.
Proactive Monitoring: Monitor system logs for repeated apmd process restarts or crash reports that may indicate an ongoing attempt to trigger this vulnerability.
Compensating Controls: While no direct virtual patch exists, ensure that access to the virtual server management interfaces is restricted to trusted networks to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The risk of service disruption to F5 BIG-IP infrastructure is significant due to the ease of exploitation. Security teams should prioritize patching the affected systems during the next maintenance window to prevent potential denial-of-service attacks that could impact operational availability.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.