cbcvebase.
CVE-2025-23412
published 2025-02-05

CVE-2025-23412: When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached…

high8.7CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

5 ranges
VendorProductVersion rangeFixed in
f5big-ip>= 16.1.3 < 16.1.516.1.5
f5big-ip>= 17.1.0 < 17.1.217.1.2
f5big-ip_access_policy_manager>= 16.1.3 < 16.1.516.1.5
f5big-ip_access_policy_manager>= 17.1.0 < 17.1.217.1.2
f5big-ip_apm