CVE-2025-54858High· 7.5▾ TwilightWhen a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
big-ip_advanced_web_application_firewall >= 15.1.0, < 15.1.10.8big-ip_advanced_web_application_firewall >= 16.1.0, < 16.1.6.1big-ip_advanced_web_application_firewall >= 17.1.0, < 17.1.3big-ip_advanced_web_application_firewall >= 17.5.0, < 17.5.1.3big-ip_application_security_manager >= 15.1.0, < 15.1.10.8big-ip_application_security_manager >= 16.1.0, < 16.1.6.1big-ip_application_security_manager >= 17.1.0, < 17.1.3big-ip_application_security_manager >= 17.5.0, < 17.5.1.3Upgrade past the affected range:
big-ip_advanced_web_application_firewall 17.5.1.3big-ip_application_security_manager 17.5.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61935High· 7.5When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-61938High· 7.5When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process …
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2022-50407Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test
CVE-2025-61933Medium· 6.1A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of…
CVE-2025-53860Medium· 4.1A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems. Note: Software versions which have reached End o…