CVE-2025-58096

Severity
8.2HIGH
EPSS
0.1%
top 75.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15

Description

When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages22 packages

NVDf5/big-ip_local_traffic_manager15.1.015.1.10.8+3
NVDf5/big-ip_global_traffic_manager15.1.015.1.10.8+2
NVDf5/big-ip_domain_name_system15.1.015.1.10.8+3
CVEListV5f5/big-ip17.5.017.5.1.3+3
NVDf5/big-ip_websafe15.1.015.1.10.8+3

🔴Vulnerability Details

2
CVEList
BIG-IP TMM vulnerability2025-10-15
GHSA
GHSA-73ww-64hw-vhw7: When the database variable tm2025-10-15

📋Vendor Advisories

2
F5
CVE-2025-58096: When the database variable tm2025-10-15
Microsoft
wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode2025-04-08