First published: Wed Feb 05 2025(Updated: )
When the Session Initiation Protocol (SIP) application layer gateway (ALG) profile and the SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Service Proxy for Kubernetes | =1.9.0>=1.8.0<=1.8.2>=1.7.0<=1.7.6 | 1.9.11.7.7 |
F5 BIG-IP | >=17.1.0<=17.1.1 | 17.1.2 |
F5 BIG-IP | >=16.1.0<=16.1.4 | 16.1.5 |
F5 BIG-IP | >=15.1.0<=15.1.10 | - |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22846 has a high severity rating as it can lead to the termination of the Traffic Management Microkernel.
To address CVE-2025-22846, upgrade to the recommended versions of F5 BIG-IP as detailed in the vendor's advisory.
CVE-2025-22846 affects specific versions of F5 BIG-IP, including versions between 1.7.0 and 1.9.0, as well as several versions in the 15.x, 16.x, and 17.x series.
F5 has not specified any workarounds for CVE-2025-22846; upgrading to a patched version is the recommended course of action.
CVE-2025-22846 can cause the Traffic Management Microkernel to terminate unexpectedly, potentially disrupting service and affecting overall performance.