CVE-2025-60016
7.5F5 · BIG-IP
A memory-related vulnerability in F5 BIG-IP allows unauthenticated attackers to cause a Traffic Management Microkernel (TMM) termination via specifically crafted traffic.
Executive summary
A memory corruption vulnerability in the Traffic Management Microkernel of F5 BIG-IP products can be exploited by unauthenticated attackers to trigger a denial of service condition.
Vulnerability
The vulnerability, categorized as an improper restriction of operations within memory bounds (CWE-119), is triggered when specific ECC Brainpool curves are configured. An unauthenticated attacker can send crafted traffic to the virtual server, causing the TMM to crash and resulting in a denial of service.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the potential for service disruption. Successful exploitation results in the termination of the Traffic Management Microkernel, leading to immediate downtime for all applications processed by the affected BIG-IP device, which can cause significant operational disruption and loss of availability for critical business services.
Remediation
Immediate Action: Upgrade to the fixed versions as specified in the F5 security advisory, specifically moving to BIG-IP 17.5.0, 16.1.0, or 15.1.0, or the appropriate versions for SPK and CNF platforms.
Proactive Monitoring: Monitor device logs for TMM process restarts and unexpected service interruptions that may indicate an exploitation attempt.
Compensating Controls: If patching is not immediately feasible, consider removing the affected ECC Brainpool curves from the SSL profiles applied to virtual servers to neutralize the attack vector.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of the TMM in maintaining BIG-IP availability, organizations should prioritize updating their firmware to the recommended fixed versions. If immediate patching is prevented by maintenance windows, the temporary removal of the vulnerable ECC Brainpool configurations is strongly advised to prevent potential service-disrupting exploitation.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.