CVE-2025-55669: BIG-IP HTTP/2 vulnerability
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55669?
The severity of CVE-2025-55669 is classified as high due to its potential to cause disruptions in traffic management.
How do I fix CVE-2025-55669?
To fix CVE-2025-55669, upgrade to the recommended versions provided by F5, specifically 17.1.2.2 or 16.1.6.
What products are affected by CVE-2025-55669?
CVE-2025-55669 affects F5 BIG-IP ASM versions 17.1.0 to 17.1.2 and 16.1.0 to 16.1.5.
What happens if CVE-2025-55669 is exploited?
If exploited, CVE-2025-55669 can cause the Traffic Management Microkernel (TMM) to terminate, leading to potential system downtime.
How can I mitigate the risks associated with CVE-2025-55669?
Mitigate the risks of CVE-2025-55669 by applying the available security updates and monitoring system logs for unusual traffic patterns.