CVE-2025-54854

7.5

F5 · BIG-IP

An out-of-bounds read vulnerability in F5 BIG-IP APM allows unauthenticated attackers to cause a denial-of-service condition by sending specially crafted traffic to an OAuth-configured virtual server.

Executive summary

A critical denial-of-service vulnerability in F5 BIG-IP systems, caused by an out-of-bounds read in the apmd process, poses a significant risk to service availability.

Vulnerability

The vulnerability is an out-of-bounds read (CWE-125) occurring within the apmd process when an OAuth access profile is active. It is exploitable by unauthenticated remote attackers who can trigger a process termination by sending crafted traffic to the affected virtual server.

Business impact

Successful exploitation results in the termination of the apmd process, leading to a denial-of-service for the affected BIG-IP modules. Given the CVSS score of 7.5, this vulnerability represents a high-severity risk to business continuity, as it can disrupt critical access management services and prevent legitimate users from authenticating or accessing protected resources.

Remediation

Immediate Action: Update the affected F5 BIG-IP systems to the specified fixed versions (e.g., 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8) as detailed in the F5 security advisory K000156602.

Proactive Monitoring: Monitor system logs for repeated apmd process restarts or crash reports that may indicate an ongoing attempt to trigger this vulnerability.

Compensating Controls: While no direct virtual patch exists, ensure that access to the virtual server management interfaces is restricted to trusted networks to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

The risk of service disruption to F5 BIG-IP infrastructure is significant due to the ease of exploitation. Security teams should prioritize patching the affected systems during the next maintenance window to prevent potential denial-of-service attacks that could impact operational availability.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.