CVE-2025-60016

7.5

F5 · BIG-IP

A memory-related vulnerability in F5 BIG-IP allows unauthenticated attackers to cause a Traffic Management Microkernel (TMM) termination via specifically crafted traffic.

Executive summary

A memory corruption vulnerability in the Traffic Management Microkernel of F5 BIG-IP products can be exploited by unauthenticated attackers to trigger a denial of service condition.

Vulnerability

The vulnerability, categorized as an improper restriction of operations within memory bounds (CWE-119), is triggered when specific ECC Brainpool curves are configured. An unauthenticated attacker can send crafted traffic to the virtual server, causing the TMM to crash and resulting in a denial of service.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the potential for service disruption. Successful exploitation results in the termination of the Traffic Management Microkernel, leading to immediate downtime for all applications processed by the affected BIG-IP device, which can cause significant operational disruption and loss of availability for critical business services.

Remediation

Immediate Action: Upgrade to the fixed versions as specified in the F5 security advisory, specifically moving to BIG-IP 17.5.0, 16.1.0, or 15.1.0, or the appropriate versions for SPK and CNF platforms.

Proactive Monitoring: Monitor device logs for TMM process restarts and unexpected service interruptions that may indicate an exploitation attempt.

Compensating Controls: If patching is not immediately feasible, consider removing the affected ECC Brainpool curves from the SSL profiles applied to virtual servers to neutralize the attack vector.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of the TMM in maintaining BIG-IP availability, organizations should prioritize updating their firmware to the recommended fixed versions. If immediate patching is prevented by maintenance windows, the temporary removal of the vulnerable ECC Brainpool configurations is strongly advised to prevent potential service-disrupting exploitation.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.