CVE-2025-24319: BIG-IP Next Central Manager vulnerability
When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24319?
CVE-2025-24319 is considered to have a critical severity due to the potential for disruption of Kubernetes services.
How do I fix CVE-2025-24319?
To fix CVE-2025-24319, ensure that your F5 BIG-IP Next Central Manager is updated to version 20.3.0 or later.
What versions of F5 BIG-IP Next Central Manager are affected by CVE-2025-24319?
F5 BIG-IP Next Central Manager versions from 20.2.0 to 20.2.1 are affected by CVE-2025-24319.
What are the implications of CVE-2025-24319 for Kubernetes services?
CVE-2025-24319 can result in the termination of the Kubernetes service running on the BIG-IP Next Central Manager node, leading to service interruptions.
Who is the vendor responsible for CVE-2025-24319?
The vendor responsible for CVE-2025-24319 is F5 Networks, which produces the BIG-IP Next Central Manager.