CVE-2025-22891: BIG-IP PEM Vulnerability
When a BIG-IP PEM Control Plane Listener virtual server is configured with a Diameter Endpoint profile, undisclosed traffic can cause the virtual server to stop processing new client connections and cause an increase in memory resource utilization.
Other sources
When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22891?
CVE-2025-22891 has been classified as a moderate severity vulnerability affecting F5 BIG-IP (PEM) configurations.
How do I fix CVE-2025-22891?
To mitigate CVE-2025-22891, upgrade to the patched versions of F5 BIG-IP (PEM) listed in the advisory: 17.1.2, 16.1.5, or applicable updates for earlier versions.
What are the symptoms of the CVE-2025-22891 vulnerability?
The symptoms of CVE-2025-22891 include the BIG-IP PEM Control Plane Listener virtual server failing to process new client connections and an increase in memory resource utilization.
Which versions of F5 BIG-IP are affected by CVE-2025-22891?
CVE-2025-22891 affects F5 BIG-IP (PEM) versions 15.1.0 through 15.1.10, 16.1.0 through 16.1.4, and 17.1.0 through 17.1.1.
Is CVE-2025-22891 specific to any configuration in BIG-IP?
Yes, CVE-2025-22891 specifically impacts configurations where the BIG-IP PEM Control Plane Listener virtual server is set up with a Diameter Endpoint profile.