CVE-2025-23412: BIG-IP APM access profile vulnerability
When a BIG-IP APM access profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
Other sources
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23412?
CVE-2025-23412 has a critical severity rating due to its potential to cause denial of service by terminating the Traffic Management Microkernel.
How do I fix CVE-2025-23412?
To address CVE-2025-23412, upgrade to the latest patched version of F5 BIG-IP APM that is beyond version 16.1.5.
Which versions of F5 BIG-IP (APM) are affected by CVE-2025-23412?
CVE-2025-23412 affects all versions from 16.1.3 to 16.1.4 inclusive of F5 BIG-IP (APM) as well as earlier versions.
What could happen if I do not address CVE-2025-23412?
Failure to address CVE-2025-23412 may result in unexpected termination of the Traffic Management Microkernel, leading to service disruptions.
Is there any workaround for CVE-2025-23412?
Currently, there are no documented workarounds for mitigating CVE-2025-23412; applying the update is the recommended approach.