CVE-2025-55036
7.5F5 · BIG-IP
A memory corruption vulnerability in the F5 BIG-IP SSL Orchestrator allows unauthenticated attackers to cause a denial of service via crafted traffic.
Executive summary
A critical memory corruption vulnerability exists in F5 BIG-IP SSL Orchestrator, which could lead to a denial of service on affected systems.
Vulnerability
The vulnerability is an out-of-bounds write (CWE-787) that occurs when processing traffic through the SSL Orchestrator explicit forward proxy feature. This flaw is remotely exploitable by an unauthenticated attacker.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk primarily due to its potential for service disruption. Successful exploitation allows an attacker to cause memory corruption, which typically results in system crashes or service instability, leading to significant downtime for critical network traffic processing.
Remediation
Immediate Action: Upgrade F5 BIG-IP software to version 17.5.0 or later to ensure the memory corruption vulnerability is resolved.
Proactive Monitoring: Review system logs for unexpected service restarts or performance degradation that may indicate an attempt to trigger the memory corruption flaw.
Compensating Controls: Disable the SSL Orchestrator explicit forward proxy feature on affected virtual servers if immediate patching is not feasible, although this will disrupt the associated proxy functionality.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for service disruption and the unauthenticated nature of the attack vector, administrators should prioritize this update. Organizations utilizing the SSL Orchestrator feature must transition to the identified fixed versions immediately to restore system integrity and maintain availability.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.