CVE-2025-61951

7.5

F5 · BIG-IP

A vulnerability in the F5 BIG-IP Traffic Management Microkernel allows unauthenticated remote attackers to trigger a service crash via specific DTLS 1.2 traffic.

Executive summary

A high-severity denial-of-service vulnerability in F5 BIG-IP allows unauthenticated attackers to terminate the Traffic Management Microkernel, disrupting critical network operations.

Vulnerability

This flaw is an out-of-bounds read (CWE-125) triggered when processing specifically crafted DTLS 1.2 traffic on virtual servers configured with specific Server SSL profiles and client authentication. The attack vector is network-based and requires no authentication, allowing any remote user to cause system instability.

Business impact

Successful exploitation results in the termination of the Traffic Management Microkernel, which is the core component responsible for processing network traffic in BIG-IP systems. This leads to a denial-of-service condition, causing significant operational downtime and impacting all services managed by the affected device. With a CVSS score of 7.5, this vulnerability represents a high risk to availability that requires immediate attention in production environments.

Remediation

Immediate Action: Upgrade affected F5 BIG-IP installations to the patched versions specified in the vendor advisory (K000151309) as soon as possible.

Proactive Monitoring: Monitor system logs for repeated TMM service restarts or crash dumps that correlate with incoming DTLS traffic patterns.

Compensating Controls: If patching is delayed, consider disabling the affected DTLS 1.2 virtual server configurations or restricting access to the management interface via strict firewall rules to prevent unauthorized traffic from reaching the vulnerable endpoint.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability poses a clear risk to network availability due to the potential for unauthenticated service disruption. Security teams should prioritize the application of vendor-supplied patches to ensure the stability of their BIG-IP infrastructure. If immediate patching is not feasible, evaluate the necessity of the specific DTLS 1.2 configurations and apply restrictive network access controls as a temporary measure.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.