CVE-2025-59478
7.5F5 · BIG-IP
A vulnerability in the F5 BIG-IP Traffic Management Microkernel allows unauthenticated remote attackers to cause a denial-of-service condition via specially crafted requests.
Executive summary
A critical denial-of-service vulnerability in F5 BIG-IP can cause the system to crash when specific DoS protection profiles are active.
Vulnerability
The flaw stems from an access of uninitialized pointer (CWE-824) within the Traffic Management Microkernel (TMM) process when a BIG-IP AFM denial-of-service protection profile is configured on a virtual server, which can be triggered by unauthenticated remote attackers.
Business impact
Successful exploitation results in the termination of the TMM process, leading to a denial-of-service for all traffic handled by the affected virtual server. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to service availability and business continuity for organizations relying on BIG-IP for critical infrastructure load balancing and security.
Remediation
Immediate Action: Administrators must upgrade to the patched versions specified in the F5 security advisory K000152341 as soon as possible.
Proactive Monitoring: Review system logs for frequent TMM process restarts or unexpected service interruptions associated with high volumes of incoming traffic.
Compensating Controls: While a permanent patch is required, ensure that logging and monitoring are configured to identify potential traffic patterns that precede TMM crashes.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete service disruption, organizations should prioritize the deployment of the vendor-supplied patches to affected F5 BIG-IP systems. Failure to address this vulnerability exposes the network perimeter to trivial denial-of-service attacks that could be launched by unauthenticated actors.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.