CVE-2025-24326: BIG-IP Advanced WAF/ASM BADoS vulnerability
When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24326?
CVE-2025-24326 has not been assigned a specific severity rating, but it involves increased memory resource utilization due to malicious traffic.
How do I fix CVE-2025-24326?
To mitigate CVE-2025-24326, ensure that your BIG-IP Advanced WAF/ASM software is updated to the latest version and reconfigure the BADoS TLS Signatures feature.
What products are affected by CVE-2025-24326?
CVE-2025-24326 affects the F5 BIG-IP Advanced WAF/ASM when the BADoS TLS Signatures feature is configured.
Can outdated software be affected by CVE-2025-24326?
Software versions of F5 BIG-IP Advanced WAF/ASM that have reached End of Technical Support (EoTS) are not evaluated for CVE-2025-24326.
What does the BADoS TLS Signatures feature do in F5 BIG-IP Advanced WAF/ASM?
The BADoS TLS Signatures feature in F5 BIG-IP Advanced WAF/ASM is designed to detect and mitigate behavioral denial-of-service attacks but may lead to increased memory utilization under certain conditions.