First published: Wed Feb 05 2025(Updated: )
When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Advanced WAF/ASM |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24326 has not been assigned a specific severity rating, but it involves increased memory resource utilization due to malicious traffic.
To mitigate CVE-2025-24326, ensure that your BIG-IP Advanced WAF/ASM software is updated to the latest version and reconfigure the BADoS TLS Signatures feature.
CVE-2025-24326 affects the F5 BIG-IP Advanced WAF/ASM when the BADoS TLS Signatures feature is configured.
Software versions of F5 BIG-IP Advanced WAF/ASM that have reached End of Technical Support (EoTS) are not evaluated for CVE-2025-24326.
The BADoS TLS Signatures feature in F5 BIG-IP Advanced WAF/ASM is designed to detect and mitigate behavioral denial-of-service attacks but may lead to increased memory utilization under certain conditions.