CVE-2025-61935: BIG-IP Advanced WAF and ASM vulnerability
When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61935?
CVE-2025-61935 is classified as a high severity vulnerability due to its potential to cause service disruption.
How do I fix CVE-2025-61935?
To mitigate CVE-2025-61935, it is recommended to upgrade to the latest version of F5 BIG-IP Advanced WAF/ASM as specified in the vendor's advisory.
Which versions of F5 BIG-IP Advanced WAF/ASM are affected by CVE-2025-61935?
CVE-2025-61935 affects F5 BIG-IP Advanced WAF/ASM versions 15.1.0 to 15.1.10, and all versions in the 17.1.x series up to 17.5.0.
What impact does CVE-2025-61935 have on my system?
CVE-2025-61935 can cause the bd process to terminate unexpectedly, leading to potential denial of service on the affected virtual servers.
Is there a workaround for CVE-2025-61935?
While the recommended action is to upgrade, temporarily adjusting security policies may minimize the risk associated with CVE-2025-61935.