CVE-2025-59478

7.5

F5 · BIG-IP

A vulnerability in the F5 BIG-IP Traffic Management Microkernel allows unauthenticated remote attackers to cause a denial-of-service condition via specially crafted requests.

Executive summary

A critical denial-of-service vulnerability in F5 BIG-IP can cause the system to crash when specific DoS protection profiles are active.

Vulnerability

The flaw stems from an access of uninitialized pointer (CWE-824) within the Traffic Management Microkernel (TMM) process when a BIG-IP AFM denial-of-service protection profile is configured on a virtual server, which can be triggered by unauthenticated remote attackers.

Business impact

Successful exploitation results in the termination of the TMM process, leading to a denial-of-service for all traffic handled by the affected virtual server. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to service availability and business continuity for organizations relying on BIG-IP for critical infrastructure load balancing and security.

Remediation

Immediate Action: Administrators must upgrade to the patched versions specified in the F5 security advisory K000152341 as soon as possible.

Proactive Monitoring: Review system logs for frequent TMM process restarts or unexpected service interruptions associated with high volumes of incoming traffic.

Compensating Controls: While a permanent patch is required, ensure that logging and monitoring are configured to identify potential traffic patterns that precede TMM crashes.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for complete service disruption, organizations should prioritize the deployment of the vendor-supplied patches to affected F5 BIG-IP systems. Failure to address this vulnerability exposes the network perimeter to trivial denial-of-service attacks that could be launched by unauthenticated actors.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.