Traffic Management Microkernel Termination in F5 BIG-IP Advanced WAF and ASM
CVE-2025-55669

8.7HIGH

Key Information:

Vendor

F5

Status
Vendor
CVE Published:
15 October 2025

What is CVE-2025-55669?

When F5 BIG-IP Advanced Web Application Firewall (WAF) and Application Security Manager (ASM) are configured with a specific security policy and a server-side HTTP/2 profile on a virtual server, it has been observed that certain undisclosed traffic patterns can lead to the premature termination of the Traffic Management Microkernel (TMM). This vulnerability emphasizes the need for ongoing evaluation and monitoring, especially for versions that are still under support.

Affected Version(s)

BIG-IP 17.1.0 < 17.1.2.2

BIG-IP 16.1.0 < 16.1.6

BIG-IP 17.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.
CVE-2025-55669 : Traffic Management Microkernel Termination in F5 BIG-IP Advanced WAF and ASM