CVE-2025-61974

7.5

F5 · BIG-IP

A memory management flaw in F5 BIG-IP products allows unauthenticated attackers to trigger increased memory utilization by sending specific requests to a virtual server with a client SSL profile.

Executive summary

A critical memory exhaustion vulnerability in F5 BIG-IP products allows unauthenticated remote attackers to cause resource degradation via crafted SSL requests.

Vulnerability

This is a memory leak vulnerability (CWE-401) where the system fails to release memory after processing specific SSL requests. The flaw is exploitable by unauthenticated remote attackers who can trigger the exhaustion of system resources.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the ease of exploitation and the potential for significant denial of service. Successful exploitation can lead to system instability, service interruptions, and potential outages for business-critical applications hosted behind the affected BIG-IP devices.

Remediation

Immediate Action: Upgrade to the specific patched versions provided in the F5 security advisory K000156733 to ensure memory is correctly managed.

Proactive Monitoring: Monitor system memory utilization and CPU load metrics for unexpected spikes that correlate with incoming traffic patterns.

Compensating Controls: Implement rate limiting or traffic shaping policies to restrict the volume of requests hitting the virtual server, which may mitigate the speed of memory depletion.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high impact of this memory leak on system stability and the relative ease of triggering the flaw, administrators must prioritize the application of the vendor-provided patches. Evaluate the affected BIG-IP environment immediately and schedule maintenance windows to update to the secure versions listed in the vendor advisory.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.