CVE-2025-47148
published 2025-10-15CVE-2025-47148: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.36%
29.1th percentile
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip | >= 17.5.0 < 17.5.1 | 17.5.1 |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_access_policy_manager | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_ssl_orchestrator | — | — |
| f5 | big-ip_ssl_orchestrator | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_ssl_orchestrator | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_ssl_orchestrator | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_sslo | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2025-47148: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Id...
vendor_f5·2025-10-15·CVSS 6.5
CVE-2025-47148 [HIGH] CWE-404 CVE-2025-47148: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Id...
CVE-2025-47148: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Id...
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP APM, BIG-IP SSLO
Affected Versions: 15.1.0 - 15.1.10.8; 16.1.0 - 16.1.6.1; 17.1.0 - 17.1.3; 17.5.0
F5 Advisory Articles: K000148816
F5 References: https://my.f5.com/manage/s/article/K000148816
GHSA
GHSA-94mj-cc39-hffh: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with singl
ghsa_unreviewed·2025-10-15
CVE-2025-47148 [HIGH] CWE-404 GHSA-94mj-cc39-hffh: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with singl
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Qualys
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
blogs_qualys·2025-10-18
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
## Table of Contents
CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscores the S
Qualys
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
blogs_qualys·2025-10-18
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
#### Table of Contents
- CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
- The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
- How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
- Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscore
Tenable
FAQ on F5 Security Incident
blogs_tenable·2025-10-15
FAQ on F5 Security Incident
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2025-10-15
Published