Access Configuration Flaw in BIG-IP APM Affects F5 Networks
CVE-2025-23412

8.7HIGH

Key Information:

Vendor
F5
Status
Vendor
CVE Published:
5 February 2025

Summary

A vulnerability exists within the BIG-IP APM Access Profile settings when deployed on a virtual server, allowing certain undisclosed requests to unexpectedly cause the Traffic Management Microkernel (TMM) to terminate. This flaw can disrupt the overall service availability and compromise the integrity of the access management process. Proper configuration and regular updates are crucial to mitigate potential exploits.

Affected Version(s)

BIG-IP 17.1.0 < 17.1.2

BIG-IP 16.1.3 < 16.1.5

BIG-IP 15.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.