First published: Wed Feb 05 2025(Updated: )
When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next Cloud-Native Network Functions | >=1.1.0<=1.3.3 | 1.4.0 |
F5 BIG-IP AFM | >=17.1.0<=17.1.1 | 17.1.2 |
F5 BIG-IP AFM | >=16.1.0<=16.1.5 | - |
F5 BIG-IP AFM | >=15.1.0<=15.1.10 | - |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-24312 has been classified as significant due to its potential to impact CPU resource utilization.
To fix CVE-2025-24312, upgrade to the recommended versions of F5 BIG-IP software as specified in the advisory.
CVE-2025-24312 affects multiple versions of F5 BIG-IP AFM and F5 BIG-IP Next CNF between specific versions.
CVE-2025-24312 can lead to increased CPU resource utilization when specific traffic is present.
Currently, there are no official workarounds for CVE-2025-24312; upgrading to the latest version is advised.