CVE-2025-58424
- EPSS 0.23%
- Veröffentlicht 15.10.2025 13:55:47
- Zuletzt bearbeitet 08.10.2026 12:10:00
On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu...
CVE-2025-61938
- EPSS 0.32%
- Veröffentlicht 15.10.2025 13:55:47
- Zuletzt bearbeitet 08.10.2026 12:10:00
When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate...
CVE-2025-55036
- EPSS 0.32%
- Veröffentlicht 15.10.2025 13:55:46
- Zuletzt bearbeitet 08.10.2026 12:10:00
When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption. Note: Software versions which have reached End of Technical Support (EoT...
CVE-2025-59781
- EPSS 0.32%
- Veröffentlicht 15.10.2025 13:55:46
- Zuletzt bearbeitet 22.10.2025 21:02:07
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-46706
- EPSS 0.4%
- Veröffentlicht 15.10.2025 13:55:45
- Zuletzt bearbeitet 21.10.2025 18:54:09
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua...
CVE-2025-55669
- EPSS 0.36%
- Veröffentlicht 15.10.2025 13:55:45
- Zuletzt bearbeitet 08.10.2026 12:10:00
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached...
CVE-2025-48008
- EPSS 0.42%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 21.10.2025 18:53:07
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions...
CVE-2025-58153
- EPSS 0.22%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 08.10.2026 12:10:00
Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS)...
CVE-2025-60016
- EPSS 0.41%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 22.10.2025 21:06:10
When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Mi...
CVE-2025-58474
- EPSS 0.36%
- Veröffentlicht 15.10.2025 13:55:43
- Zuletzt bearbeitet 22.10.2025 21:00:17
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software ve...