CVE-2025-61935

7.5

F5 · BIG-IP

Undisclosed requests sent to a virtual server with an F5 BIG-IP Advanced WAF or ASM security policy can cause the bd process to terminate, resulting in a denial of service condition.

Executive summary

A vulnerability in F5 BIG-IP allows unauthenticated attackers to trigger a denial of service by causing the bd process to crash via specifically crafted requests.

Vulnerability

This is a denial of service vulnerability stemming from an unchecked return value (CWE-252) within the Advanced WAF or ASM component. The vulnerability is exploitable by an unauthenticated attacker over the network.

Business impact

The successful exploitation of this vulnerability results in the termination of the bd process, which directly impacts the availability of the F5 BIG-IP system. Given a CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity by enabling attackers to disrupt critical traffic inspection and security policy enforcement, potentially leading to widespread service outages.

Remediation

Immediate Action: Upgrade to the patched versions identified in the F5 security advisory K000154664 to resolve the underlying process stability issue.

Proactive Monitoring: Monitor system logs for frequent restarts of the bd process or sudden spikes in service traffic that coincide with process crashes.

Compensating Controls: Ensure that access to the management interface is restricted and consider implementing rate limiting on traffic directed at virtual servers to mitigate the impact of potential DoS attempts.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

This vulnerability represents a significant risk to the availability of F5 BIG-IP infrastructure. Administrators should prioritize patching the affected systems to the recommended versions as soon as possible to prevent potential denial of service attacks against their security policy enforcement layers.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.