Elliptic Curve Cryptography Vulnerability in F5 Networks Product
CVE-2025-60016

8.7HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
15 October 2025

What is CVE-2025-60016?

A vulnerability exists in F5 Networks' products when using Diffie-Hellman group Elliptic Curve Cryptography with Brainpool curves in SSL profiles. When this configuration is applied to a virtual server, it may inadvertently trigger the Traffic Management Microkernel to terminate, resulting in service disruption. This vulnerability highlights the potential risks associated with improperly configured cryptographic algorithms in critical network management components.

Affected Version(s)

BIG-IP 17.1.0 < 17.1.2

BIG-IP Next CNF 1.1.0 < 1.4.0

BIG-IP Next SPK 1.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.