CVE-2025-20045
published 2025-02-05CVE-2025-20045: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.6th percentile
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < * | * |
| f5 | big-ip | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip | >= 17.1.0 < 17.1.2 | 17.1.2 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_access_policy_manager | >= 17.1.0 < 17.1.2 | 17.1.2 |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 17.1.0 < 17.1.2 | 17.1.2 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_advanced_web_application_firewall | >= 17.1.0 < 17.1.2 | 17.1.2 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_analytics | >= 17.1.0 < 17.1.2 | 17.1.2 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_application_acceleration_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_application_acceleration_manager | >= 17.1.0 < 17.1.2 | 17.1.2 |
| f5 | big-ip_application_security_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_application_security_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g7gf-f662-24xm: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routin
ghsa_unreviewed·2025-02-05
CVE-2025-20045 [HIGH] CWE-476 GHSA-g7gf-f662-24xm: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routin
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2025-20045: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile a...
vendor_f5·2025-02-05·CVSS 7.5
CVE-2025-20045 [HIGH] CWE-476 CVE-2025-20045: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile a...
CVE-2025-20045: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile a...
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, Big-Ip A
Suricata
ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M1
suricata·2025-04-18·CVSS 9.8
CVE-2021-20045 [CRITICAL] ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M1
ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M1
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M1"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/fileshare/sonicfiles|2f 3f|"; fast_pattern; content:"User|3d|"; pcre:"/^[^\x26]{136,}/R"; content:"RacNumber|3d|36"; reference:url,www.nccgroup.com/us/research-blog/technical-advisory-sonicwall-sma-100-series-multiple-unauthenticated-heap-based-and-stack-based-buffer-overflow-cve-2021-20045/; reference:cve,2021-20045; classtype:web-application-attack; sid:2061730; rev:1; metadata:affected_product SonicWall, attack_target Server, tls_state TLSDecrypt, created_at 2025_04_18, cve CVE_2021_20045, de
Suricata
ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M2
suricata·2025-04-18·CVSS 9.8
CVE-2021-20045 [CRITICAL] ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M2
ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M2
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER SonicWall SMA Unauthenticated Stack Buffer Overflow (CVE-2021-20045) M2"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/fileshare/sonicfiles|2f 3f|"; fast_pattern; content:"Pass|3d|"; pcre:"/^[^\x26]{136,}/R"; content:"RacNumber|3d|36"; reference:url,www.nccgroup.com/us/research-blog/technical-advisory-sonicwall-sma-100-series-multiple-unauthenticated-heap-based-and-stack-based-buffer-overflow-cve-2021-20045/; reference:cve,2021-20045; classtype:web-application-attack; sid:2061731; rev:1; metadata:affected_product SonicWall, attack_target Server, tls_state TLSDecrypt, created_at 2025_04_18, cve CVE_2021_20045, de
Suricata
ET WEB_SERVER SonicWall SMA Unauthenticated Heap Buffer Overflow (CVE-2021-20045)
suricata·2025-04-18·CVSS 9.8
CVE-2021-20045 [CRITICAL] ET WEB_SERVER SonicWall SMA Unauthenticated Heap Buffer Overflow (CVE-2021-20045)
ET WEB_SERVER SonicWall SMA Unauthenticated Heap Buffer Overflow (CVE-2021-20045)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER SonicWall SMA Unauthenticated Heap Buffer Overflow (CVE-2021-20045)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/fileshare/sonicfiles|2f 3f|"; fast_pattern; content:"Domn|3d|"; pcre:"/^[^\x26]{128,}/R"; content:"RacNumber|3d|36"; reference:url,www.nccgroup.com/us/research-blog/technical-advisory-sonicwall-sma-100-series-multiple-unauthenticated-heap-based-and-stack-based-buffer-overflow-cve-2021-20045/; reference:cve,2021-20045; classtype:web-application-attack; sid:2061732; rev:1; metadata:affected_product SonicWall, attack_target Server, tls_state TLSDecrypt, created_at 2025_04_18, cve CVE_2021_20045, deployment
No public exploits indexed.
No writeups or analysis indexed.
2025-02-05
Published