CVE-2025-59478: BIG-IP AFM DoS protection profile vulnerability
When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59478?
CVE-2025-59478 has been categorized as a denial-of-service vulnerability affecting F5 BIG-IP AFM.
How do I fix CVE-2025-59478?
To remediate CVE-2025-59478, upgrade your F5 BIG-IP AFM software to the fixed versions provided by F5.
What products are affected by CVE-2025-59478?
CVE-2025-59478 affects F5 BIG-IP AFM versions 17.5.0, 17.1.0 through 17.1.2, and 15.1.0 through 15.1.10.
What type of attack does CVE-2025-59478 allow?
CVE-2025-59478 allows undisclosed requests to terminate the Traffic Management Microkernel, leading to a denial-of-service condition.
Is there a workaround for CVE-2025-59478?
There are no specific workarounds suggested for CVE-2025-59478, and the recommended action is to apply the appropriate software update.