CVE-2025-55669

7.5

F5 · BIG-IP

A vulnerability in F5 BIG-IP Advanced WAF and ASM allows unauthenticated remote attackers to trigger a Traffic Management Microkernel (TMM) termination via specifically crafted HTTP/2 traffic.

Executive summary

A denial of service vulnerability in F5 BIG-IP allows unauthenticated attackers to crash the Traffic Management Microkernel, resulting in service disruption.

Vulnerability

The flaw, categorized as CWE-672, occurs when an Advanced WAF and ASM security policy is combined with a server-side HTTP/2 profile. An unauthenticated attacker can send crafted traffic that causes the TMM to terminate, effectively creating a denial of service condition.

Business impact

The ability for an unauthenticated remote attacker to crash the TMM process directly impacts the availability of critical network infrastructure. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to business continuity, as it allows for the disruption of services managed by the BIG-IP platform without requiring any prior system access.

Remediation

Immediate Action: Update to the fixed versions as specified by the vendor, specifically versions 17.5.0 or 15.1.0 and later, to resolve the underlying resource handling error.

Proactive Monitoring: Monitor TMM logs and system health dashboards for unexpected service restarts or crash reports that coincide with spikes in HTTP/2 traffic patterns.

Compensating Controls: If immediate patching is not feasible, consider disabling the HTTP/2 profile on virtual servers where the Advanced WAF and ASM security policies are active to prevent the trigger condition.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete service disruption and the lack of authentication required to trigger the crash, this vulnerability should be prioritized for remediation. IT administrators are advised to verify their BIG-IP configurations and apply the recommended software updates immediately to ensure system stability and availability.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.