CVE-2025-61974: BIG-IP SSL/TLS vulnerability
Published Oct 15, 2025
·Updated
When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Affected Software
14 affected componentsFixes available
F5 BIG-IP Next SPK>=2.0.0<=2.0.2
2.1.0-
F5 BIG-IP Next SPK>=1.7.0<=1.9.2
1.7.14-
F5 BIG-IP Next CNF>=2.0.0<=2.1.0
2.1.0-
F5 BIG-IP Next CNF>=1.1.0<=1.4.1
1.4.0-
F5 BIG-IP Next for Kubernetes>=2.0.0<=2.1.0
2.1.0-
F5 BIG-IP>=17.5.0<=17.5.1, >=17.1.0<=17.1.2
17.5.1.317.1.3
F5 BIG-IP>=16.1.0<=16.1.6
16.1.6.1
F5 BIG-IP>=15.1.0<=15.1.10
15.1.10.8
F5 Big-ip Next Cloud-native Network Functions>=1.1.0<=1.4.1
F5 Big-ip Next Cloud-native Network Functions>=2.0.0<=2.1.0
F5 BIG-IP Next for Kubernetes=2.0.0
F5 BIG-IP Next for Kubernetes=2.1.0
F5 Big-ip Next Service Proxy For Kubernetes>=1.7.0<=1.9.2
F5 Big-ip Next Service Proxy For Kubernetes>=2.0.0<=2.0.2
Event History
Oct 15, 2025
Advisory Published
via F5·11:16 AM
Data Sourced
via F5·11:16 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61974?
CVE-2025-61974 has a high severity due to its impact on memory resource utilization.
2
What versions are affected by CVE-2025-61974?
Versions of F5 BIG-IP Next SPK, BIG-IP Next CNF, and BIG-IP Next for Kubernetes within the specified ranges are affected by CVE-2025-61974.
3
How do I fix CVE-2025-61974?
To fix CVE-2025-61974, you must upgrade to the recommended versions provided by F5 in their advisory.
4
What types of systems are impacted by CVE-2025-61974?
CVE-2025-61974 impacts multiple F5 products including BIG-IP and its various Next service configurations.
5
What potential symptoms should I look for with CVE-2025-61974?
You may observe increased memory resource utilization on virtual servers configured with a client SSL profile as a symptom of CVE-2025-61974.