8.7
CVE-2025-24312
- EPSS 0.34%
- Veröffentlicht 05.02.2025 18:15:34
- Zuletzt bearbeitet 12.11.2025 16:38:01
- Quelle f5sirt@f5.com
- CVE-Watchlists
- Unerledigt
When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Advanced Firewall Manager Version >= 15.1.0 < 15.1.10.6.0.11.6
F5 ≫ Big-ip Advanced Firewall Manager Version >= 16.1.0 < 16.1.5.2.0.7.5
F5 ≫ Big-ip Advanced Firewall Manager Version >= 17.1.0 < 17.1.2
F5 ≫ Big-ip Next Cloud-native Network Functions Version >= 1.1.0 < 1.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.563 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f5sirt@f5.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| f5sirt@f5.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.