F5-K000137709: High severity f5 big-ip next (ltm) vulnerability
Published May 7, 2025
·Updated
When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Affected Software
8 affected componentsFixes available
F5 BIG-IP Next=20.2.0
20.2.1
F5 BIG-IP Next SPK
F5 BIG-IP Next SPK>=1.8.0<=1.9.2, >=1.7.0<=1.7.11
1.7.12
F5 BIG-IP Next CNF
F5 BIG-IP Next CNF>=1.1.0<=1.2.1
1.3.0
F5 BIG-IP=17.1.0
17.1.1
F5 BIG-IP>=16.1.0<=16.1.3
16.1.4
F5 BIG-IP>=15.1.0<=15.1.8
15.1.9
Event History
May 7, 2025
Advisory Published
via F5·12:39 PM
Frequently Asked Questions
1
What is the severity of F5-K000137709?
The severity of F5-K000137709 is classified as a potential denial of service due to increased memory resource utilization.
2
How do I fix F5-K000137709?
You can remediate F5-K000137709 by upgrading to the appropriate fixed version as specified in the F5 advisory.
3
Which F5 products are impacted by F5-K000137709?
F5-K000137709 affects various versions of F5 BIG-IP, BIG-IQ, and BIG-IP Next products.
4
What type of attack does F5-K000137709 relate to?
F5-K000137709 relates to an attack that exploits the Stream Control Transmission Protocol (SCTP) configuration.
5
Is there a workaround for F5-K000137709?
Currently, there are no known workarounds for F5-K000137709; upgrading is the recommended approach.