Memory Resource Utilization Issue in F5 Networks Virtual Server with SCTP Profile
CVE-2025-41399

8.7HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
7 May 2025

What is CVE-2025-41399?

A memory resource utilization issue exists in F5 Networks' virtual servers configured with a Stream Control Transmission Protocol (SCTP) profile. This vulnerability may result from undisclosed requests, leading to increased memory usage that could affect server performance. It's important to note that software versions that have reached End of Technical Support (EoTS) are not assessed for this vulnerability, potentially leaving them exposed to risks.

Affected Version(s)

BIG-IP 17.1.0 < 17.1.1

BIG-IP 16.1.0 < 16.1.4

BIG-IP 15.1.0 < 15.1.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.
CVE-2025-41399 : Memory Resource Utilization Issue in F5 Networks Virtual Server with SCTP Profile