CVE-2025-54854: BigIP APM Vulnerability
Published Oct 15, 2025
·Updated
When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.
Affected Software
7 affected componentsFixes available
F5 BIG-IP APM>=17.5.0<=17.5.1, >=17.1.0<=17.1.2
17.5.1.317.1.3
F5 BIG-IP APM>=16.1.0<=16.1.6
16.1.6.1
F5 BIG-IP APM>=15.1.0<=15.1.10
15.1.10.8
F5 BIG-IP Access Policy Manager>=15.1.0<15.1.10.8
F5 BIG-IP Access Policy Manager>=16.1.0<16.1.6.1
F5 BIG-IP Access Policy Manager>=17.1.0<17.1.3
F5 BIG-IP Access Policy Manager>=17.5.0<=17.5.1
Event History
Oct 15, 2025
Advisory Published
via F5·11:16 AM
Data Sourced
via F5·11:16 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54854?
The severity of CVE-2025-54854 is currently classified as high due to the potential for the apmd process to terminate unexpectedly.
2
How do I fix CVE-2025-54854?
To fix CVE-2025-54854, upgrade to the recommended versions of BIG-IP APM as specified in the vendor's advisory.
3
Which versions of F5 BIG-IP APM are affected by CVE-2025-54854?
The affected versions of F5 BIG-IP APM include versions between 17.1.0 and 17.1.2, 17.5.0 and 17.5.1, and 16.1.0 and 16.1.6.
4
What impact does CVE-2025-54854 have on BIG-IP APM?
CVE-2025-54854 can cause the apmd process to terminate, potentially leading to service disruption.
5
Is there a specific patch version for CVE-2025-54854?
Yes, the specific patch versions for CVE-2025-54854 are 17.5.1.317.1.3, 16.1.6.1, and 15.1.10.8.