CVE-2025-59778
7.5F5 · F5OS-C
A resource exhaustion vulnerability in F5OS-C allows unauthenticated attackers to cause container termination by sending specific traffic when the Allowed IP Addresses feature is enabled.
Executive summary
A high-severity resource exhaustion vulnerability in F5 F5OS-C allows unauthenticated attackers to trigger a denial of service by causing critical system containers to terminate.
Vulnerability
The vulnerability is categorized as a resource management flaw (CWE-770), where the control plane fails to properly handle undisclosed traffic patterns while the Allowed IP Addresses feature is active. This allows an unauthenticated, remote attacker to exhaust system resources and force multiple containers to terminate.
Business impact
This flaw poses a significant risk to service availability, as it enables an attacker to disrupt the control plane of the F5OS-C platform. With a CVSS score of 7.5, the vulnerability is classified as High, reflecting the potential for complete service interruption of the affected chassis. Organizations relying on these devices for traffic management may experience critical downtime and loss of administrative control during an exploitation event.
Remediation
Immediate Action: Upgrade the F5OS-C chassis firmware to the corrected versions specified in F5 security advisory K000151718 to ensure resource limits are properly enforced.
Proactive Monitoring: Monitor system logs for unexpected container restarts or service crashes on the control plane that coincide with spikes in traffic directed at the management interface.
Compensating Controls: Restrict access to the management interface to trusted administrative networks only, effectively limiting the scope of potential attackers who can reach the vulnerable control plane functions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for total service disruption, administrators should prioritize patching the affected F5OS-C environments immediately. While no public exploits are currently confirmed, the nature of the flaw makes it a target for denial of service attacks, necessitating prompt action to stabilize the infrastructure.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.