CVE-2025-60016: BIG-IP SSL/TLS vulnerability
When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60016?
CVE-2025-60016 is classified as a critical vulnerability due to the potential for Traffic Management Microkernel termination.
How do I fix CVE-2025-60016?
To fix CVE-2025-60016, update to the latest version of F5 BIG-IP or F5 BIG-IP Next products as specified in the vulnerability advisory.
What versions of F5 BIG-IP are affected by CVE-2025-60016?
CVE-2025-60016 affects various versions of F5 BIG-IP and F5 BIG-IP Next products, particularly those listed before remediation.
What kind of impact does CVE-2025-60016 have on system operations?
CVE-2025-60016 can lead to unexpected termination of the Traffic Management Microkernel, impacting system availability.
Is there a workaround for CVE-2025-60016?
Currently, the best approach for CVE-2025-60016 is to apply the necessary updates as there are no known effective workarounds.