8.7
CVE-2025-54479
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:49
- Zuletzt bearbeitet 21.10.2025 19:50:56
- Quelle f5sirt@f5.com
- CVE-Watchlists
- Unerledigt
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Next Cloud-native Network Functions Version >= 1.1.0 <= 1.4.0
F5 ≫ Big-ip Next Cloud-native Network Functions Version2.0.0
F5 ≫ Big-ip Next Cloud-native Network Functions Version2.0.1
F5 ≫ Big-ip Next Cloud-native Network Functions Version2.0.2
F5 ≫ Big-ip Next Cloud-native Network Functions Version2.1.0
F5 ≫ Big-ip Next For Kubernetes Version2.0.0
F5 ≫ Big-ip Next For Kubernetes Version2.1.0
F5 ≫ Big-ip Policy Enforcement Manager Version >= 15.1.0 < 15.1.10.8
F5 ≫ Big-ip Policy Enforcement Manager Version >= 16.1.0 < 16.1.6.1
F5 ≫ Big-ip Policy Enforcement Manager Version >= 17.1.0 < 17.1.3
F5 ≫ Big-ip Policy Enforcement Manager Version17.5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.296 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f5sirt@f5.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| f5sirt@f5.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.