CVE-2025-61974
7.5F5 · BIG-IP
A memory management flaw in F5 BIG-IP products allows unauthenticated attackers to trigger increased memory utilization by sending specific requests to a virtual server with a client SSL profile.
Executive summary
A critical memory exhaustion vulnerability in F5 BIG-IP products allows unauthenticated remote attackers to cause resource degradation via crafted SSL requests.
Vulnerability
This is a memory leak vulnerability (CWE-401) where the system fails to release memory after processing specific SSL requests. The flaw is exploitable by unauthenticated remote attackers who can trigger the exhaustion of system resources.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the ease of exploitation and the potential for significant denial of service. Successful exploitation can lead to system instability, service interruptions, and potential outages for business-critical applications hosted behind the affected BIG-IP devices.
Remediation
Immediate Action: Upgrade to the specific patched versions provided in the F5 security advisory K000156733 to ensure memory is correctly managed.
Proactive Monitoring: Monitor system memory utilization and CPU load metrics for unexpected spikes that correlate with incoming traffic patterns.
Compensating Controls: Implement rate limiting or traffic shaping policies to restrict the volume of requests hitting the virtual server, which may mitigate the speed of memory depletion.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high impact of this memory leak on system stability and the relative ease of triggering the flaw, administrators must prioritize the application of the vendor-provided patches. Evaluate the affected BIG-IP environment immediately and schedule maintenance windows to update to the secure versions listed in the vendor advisory.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.