CVE-2025-54479: BIG-IP PEM vulnerability
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54479?
CVE-2025-54479 is classified with a high severity due to its potential to allow undetected traffic that can cause system termination.
How do I fix CVE-2025-54479?
To remediate CVE-2025-54479, upgrade to the appropriate fixed version specified for your F5 BIG-IP software.
What are the affected versions for CVE-2025-54479?
CVE-2025-54479 affects specific versions of F5 BIG-IP Next CNF, BIG-IP Next for Kubernetes, and BIG-IP PEM across various releases.
Can CVE-2025-54479 lead to a denial-of-service condition?
Yes, CVE-2025-54479 can result in a denial-of-service condition by terminating the Traffic Management Microkernel.
Is there a workaround for CVE-2025-54479?
Currently, the recommended action for CVE-2025-54479 is to apply the necessary software upgrade, as no viable workaround has been documented.