Traffic Management Microkernel Vulnerability in F5 Networks Products
CVE-2025-36557
8.7HIGH
What is CVE-2025-36557?
A vulnerability exists within the Traffic Management Microkernel (TMM) of F5 Networks' products, where an HTTP profile configured with the Enforce RFC Compliance option can lead to instability. Undisclosed requests targeting the server may cause unexpected termination of the TMM, resulting in denial of service. It is crucial for users to ensure that they are running supported versions and to evaluate their configurations to mitigate risks.
Affected Version(s)
BIG-IP 17.5.0
BIG-IP 17.1.0 < 17.1.2
BIG-IP 16.1.0 < 16.1.5