CVE-2025-53856High· 7.5▾ TwilightWhen a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Micr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. To determine which BIG-IP platforms have an ePVA chip refer to K12837: Overview of the ePVA feature https://my.f5.com/manage/s/article/K12837 . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
big-ip_access_policy_manager >= 15.1.0, < 15.1.10.8big-ip_advanced_firewall_manager >= 15.1.0, < 15.1.10.8big-ip_advanced_web_application_firewall >= 15.1.0, < 15.1.10.8big-ip_analytics >= 15.1.0, < 15.1.10.8big-ip_application_acceleration_manager >= 15.1.0, < 15.1.10.8big-ip_application_security_manager >= 15.1.0, < 15.1.10.8big-ip_application_visibility_and_reporting >= 15.1.0, < 15.1.10.8big-ip_automation_toolchain >= 15.1.0, < 15.1.10.8big-ip_carrier-grade_nat >= 15.1.0, < 15.1.10.8big-ip_container_ingress_services >= 15.1.0, < 15.1.10.8big-ip_ddos_hybrid_defender >= 15.1.0, < 15.1.10.8big-ip_domain_name_system >= 15.1.0, < 15.1.10.8big-ip_edge_gateway >= 15.1.0, < 15.1.10.8big-ip_fraud_protection_service >= 15.1.0, < 15.1.10.8big-ip_global_traffic_manager >= 15.1.0, < 15.1.10.8big-ip_link_controller >= 15.1.0, < 15.1.10.8big-ip_local_traffic_manager >= 15.1.0, < 15.1.10.8big-ip_policy_enforcement_manager >= 15.1.0, < 15.1.10.8big-ip_ssl_orchestrator >= 15.1.0, < 15.1.10.8big-ip_webaccelerator >= 15.1.0, < 15.1.10.8big-ip_websafe >= 15.1.0, < 15.1.10.8big-ip_access_policy_manager >= 16.1.0, < 16.1.6.1big-ip_advanced_firewall_manager >= 16.1.0, < 16.1.6.1big-ip_advanced_web_application_firewall >= 16.1.0, < 16.1.6.1big-ip_analytics >= 16.1.0, < 16.1.6.1big-ip_application_acceleration_manager >= 16.1.0, < 16.1.6.1big-ip_application_security_manager >= 16.1.0, < 16.1.6.1big-ip_application_visibility_and_reporting >= 16.1.0, < 16.1.6.1big-ip_automation_toolchain >= 16.1.0, < 16.1.6.1big-ip_carrier-grade_nat >= 16.1.0, < 16.1.6.1big-ip_container_ingress_services >= 16.1.0, < 16.1.6.1big-ip_ddos_hybrid_defender >= 16.1.0, < 16.1.6.1big-ip_domain_name_system >= 16.1.0, < 16.1.6.1big-ip_edge_gateway >= 16.1.0, < 16.1.6.1big-ip_fraud_protection_service >= 16.1.0, < 16.1.6.1big-ip_global_traffic_manager >= 16.1.0, < 16.1.6.1big-ip_link_controller >= 16.1.0, < 16.1.6.1big-ip_local_traffic_manager >= 16.1.0, < 16.1.6.1big-ip_policy_enforcement_manager >= 16.1.0, < 16.1.6.1big-ip_ssl_orchestrator >= 16.1.0, < 16.1.6.1big-ip_webaccelerator >= 16.1.0, < 16.1.6.1big-ip_websafe >= 16.1.0, < 16.1.6.1big-ip_access_policy_manager >= 17.1.0, < 17.1.3big-ip_access_policy_manager >= 17.5.0, <= 17.5.1big-ip_advanced_firewall_manager >= 17.1.0, < 17.1.3big-ip_advanced_firewall_manager >= 17.5.0, <= 17.5.1big-ip_advanced_web_application_firewall >= 17.1.0, < 17.1.3big-ip_advanced_web_application_firewall >= 17.5.0, <= 17.5.1big-ip_analytics >= 17.1.0, < 17.1.3big-ip_analytics >= 17.5.0, <= 17.5.1big-ip_application_acceleration_manager >= 17.1.0, < 17.1.3big-ip_application_acceleration_manager >= 17.5.0, <= 17.5.1big-ip_application_security_manager >= 17.1.0, < 17.1.3big-ip_application_security_manager >= 17.5.0, <= 17.5.1big-ip_application_visibility_and_reporting >= 17.1.0, < 17.1.3big-ip_application_visibility_and_reporting >= 17.5.0, <= 17.5.1big-ip_automation_toolchain >= 17.1.0, < 17.1.3big-ip_automation_toolchain >= 17.5.0, <= 17.5.1big-ip_carrier-grade_nat >= 17.1.0, < 17.1.3big-ip_carrier-grade_nat >= 17.5.0, <= 17.5.1big-ip_container_ingress_services >= 17.1.0, < 17.1.3big-ip_container_ingress_services >= 17.5.0, <= 17.5.1big-ip_ddos_hybrid_defender >= 17.1.0, < 17.1.3big-ip_ddos_hybrid_defender >= 17.5.0, <= 17.5.1big-ip_domain_name_system >= 17.1.0, < 17.1.3big-ip_domain_name_system >= 17.5.0, <= 17.5.1big-ip_edge_gateway >= 17.1.0, < 17.1.3big-ip_edge_gateway >= 17.5.0, <= 17.5.1big-ip_fraud_protection_service >= 17.1.0, < 17.1.3big-ip_fraud_protection_service >= 17.5.0, <= 17.5.1big-ip_global_traffic_manager >= 17.1.0, < 17.1.3big-ip_link_controller >= 17.1.0, < 17.1.3big-ip_link_controller >= 17.5.0, <= 17.5.1big-ip_local_traffic_manager >= 17.1.0, < 17.1.3big-ip_local_traffic_manager >= 17.5.0, <= 17.5.1big-ip_policy_enforcement_manager >= 17.1.0, < 17.1.3big-ip_policy_enforcement_manager >= 17.5.0, <= 17.5.1big-ip_ssl_orchestrator >= 17.1.0, < 17.1.3big-ip_ssl_orchestrator >= 17.5.0, <= 17.5.1big-ip_webaccelerator >= 17.1.0, < 17.1.3big-ip_webaccelerator >= 17.5.0, <= 17.5.1big-ip_websafe >= 17.1.0, < 17.1.3big-ip_websafe >= 17.5.0, <= 17.5.1Upgrade past the affected range:
big-ip_access_policy_manager 17.1.3big-ip_advanced_firewall_manager 17.1.3big-ip_advanced_web_application_firewall 17.1.3big-ip_analytics 17.1.3big-ip_application_acceleration_manager 17.1.3big-ip_application_security_manager 17.1.3big-ip_application_visibility_and_reporting 17.1.3big-ip_automation_toolchain 17.1.3big-ip_carrier-grade_nat 17.1.3big-ip_container_ingress_services 17.1.3big-ip_ddos_hybrid_defender 17.1.3big-ip_domain_name_system 17.1.3big-ip_edge_gateway 17.1.3big-ip_fraud_protection_service 17.1.3big-ip_global_traffic_manager 17.1.3big-ip_link_controller 17.1.3big-ip_local_traffic_manager 17.1.3big-ip_policy_enforcement_manager 17.1.3big-ip_ssl_orchestrator 17.1.3big-ip_webaccelerator 17.1.3big-ip_websafe 17.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61933Medium· 6.1A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of…
CVE-2025-61951High· 7.5Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagram Transport Layer Security (DTLS) 1.2 virtual server is enabled with a Server SSL profile that is configured with a …
CVE-2025-61960High· 7.5When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Suppo…
CVE-2025-59269Medium· 6.1A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions whic…
CVE-2025-59481High· 8.7A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges. …
CVE-2025-59483Medium· 6.5A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.