Undisclosed Request Vulnerability in F5 BIG-IP Virtual Server Configuration
CVE-2025-24497

8.7HIGH

Key Information:

Vendor
F5
Status
Vendor
CVE Published:
5 February 2025

Summary

This vulnerability involves the F5 BIG-IP system, specifically when URL categorization is configured on a virtual server. Undisclosed requests can trigger a failure in TMM (Traffic Management Microkernel), leading to service disruption. It's important to note that versions of the software that have reached End of Technical Support (EoTS) are not included in the evaluation.

Affected Version(s)

BIG-IP 17.1.0 < 17.1.2

BIG-IP 16.1.0

BIG-IP 15.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.