CVE-2025-61938
- EPSS 0.23%
- Veröffentlicht 15.10.2025 13:55:47
- Zuletzt bearbeitet 21.10.2025 20:30:15
When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate...
CVE-2025-59781
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:46
- Zuletzt bearbeitet 22.10.2025 21:02:07
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-55036
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:46
- Zuletzt bearbeitet 21.10.2025 20:08:11
When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption. Note: Software versions which have reached End of Technical Support (EoT...
CVE-2025-55669
- EPSS 0.27%
- Veröffentlicht 15.10.2025 13:55:45
- Zuletzt bearbeitet 22.10.2025 19:18:59
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached...
CVE-2025-46706
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:45
- Zuletzt bearbeitet 21.10.2025 18:54:09
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua...
CVE-2025-48008
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 21.10.2025 18:53:07
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions...
CVE-2025-58153
- EPSS 0.09%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 27.01.2026 13:30:37
Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS)...
CVE-2025-60016
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 22.10.2025 21:06:10
When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Mi...
CVE-2025-58474
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:43
- Zuletzt bearbeitet 22.10.2025 21:00:17
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software ve...
CVE-2025-59478
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:43
- Zuletzt bearbeitet 22.10.2025 21:00:40
When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical...