CVE-2025-55036: BIG-IP SSL Orchestrator vulnerability

Published Oct 15, 2025
·
Updated

When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption.

Affected Software

6 affected componentsFixes available
F5 BIG-IP SSL Orchestrator>=17.1.0<=17.1.2
17.1.3
F5 BIG-IP SSL Orchestrator>=16.1.0<=16.1.5
16.1.6
F5 BIG-IP SSL Orchestrator>=15.1.0<=15.1.10
15.1.10.8
F5 BIG-IP SSL Orchestrator>=15.1.0<15.1.10.8
F5 BIG-IP SSL Orchestrator>=16.1.0<16.1.6
F5 BIG-IP SSL Orchestrator>=17.1.0<17.1.3

Event History

Oct 15, 2025
Advisory Published
via F5·11:16 AM
Data Sourced
via F5·11:16 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-55036?

CVE-2025-55036 has a high severity due to the potential for memory corruption affecting the BIG-IP SSL Orchestrator.

2

How do I fix CVE-2025-55036?

To fix CVE-2025-55036, upgrade to the recommended versions of F5 BIG-IP SSL Orchestrator: 17.1.3, 16.1.6, or 15.1.10.8.

3

Which versions of F5 BIG-IP SSL Orchestrator are affected by CVE-2025-55036?

Affected versions include F5 BIG-IP SSL Orchestrator versions from 15.1.0 to 15.1.10, from 16.1.0 to 16.1.5, and from 17.1.0 to 17.1.2.

4

What could be the consequences of not addressing CVE-2025-55036?

Not addressing CVE-2025-55036 could result in potential memory corruption, leading to degraded service or application crashes.

5

Is CVE-2025-55036 being actively exploited?

As of now, there are no public reports indicating active exploitation of CVE-2025-55036.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203