CVE-2025-55036: BIG-IP SSL Orchestrator vulnerability
When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55036?
CVE-2025-55036 has a high severity due to the potential for memory corruption affecting the BIG-IP SSL Orchestrator.
How do I fix CVE-2025-55036?
To fix CVE-2025-55036, upgrade to the recommended versions of F5 BIG-IP SSL Orchestrator: 17.1.3, 16.1.6, or 15.1.10.8.
Which versions of F5 BIG-IP SSL Orchestrator are affected by CVE-2025-55036?
Affected versions include F5 BIG-IP SSL Orchestrator versions from 15.1.0 to 15.1.10, from 16.1.0 to 16.1.5, and from 17.1.0 to 17.1.2.
What could be the consequences of not addressing CVE-2025-55036?
Not addressing CVE-2025-55036 could result in potential memory corruption, leading to degraded service or application crashes.
Is CVE-2025-55036 being actively exploited?
As of now, there are no public reports indicating active exploitation of CVE-2025-55036.