CVE-2025-58071

7.5

F5 · BIG-IP

A vulnerability in F5 BIG-IP systems allows unauthenticated remote attackers to cause a Traffic Management Microkernel (TMM) termination via specially crafted IPsec traffic.

Executive summary

A critical denial of service vulnerability in F5 BIG-IP systems, triggered by unauthenticated IPsec traffic, can force a system-wide service interruption.

Vulnerability

This vulnerability is caused by the use of an uninitialized variable (CWE-457) when IPsec is configured, which can be triggered by an unauthenticated remote attacker through undisclosed traffic patterns to cause a TMM crash.

Business impact

Successful exploitation results in the termination of the Traffic Management Microkernel, leading to a denial of service for the affected BIG-IP device. Given the CVSS score of 7.5, this high-severity flaw threatens the availability of critical network infrastructure, potentially causing significant operational downtime for services relying on the BIG-IP system.

Remediation

Immediate Action: Apply the vendor-supplied security updates listed in F5 advisory K000156746 to address the vulnerability in the TMM process.

Proactive Monitoring: Monitor system logs for unexpected TMM service restarts or crash reports that correlate with high volumes of IPsec traffic.

Compensating Controls: If patching is delayed, consider restricting IPsec traffic to known, trusted endpoints via upstream firewall rules to prevent unauthorized traffic from reaching the vulnerable interface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The potential for a denial of service on critical network infrastructure makes this vulnerability a high priority for remediation. Administrators should verify their current BIG-IP version against the affected releases and prioritize the installation of the appropriate patches to ensure system stability and availability.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.