Resource exhaustion in BIG-IP Next CNF and BIG-IP AFM - CVE-2025-24312
Published: February 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy. A remote attacker can send specially crafted traffic to the system and perform a denial of service (DoS) attack.
Affected software
BIG-IP AFM
How to mitigate CVE-2025-24312
BIG-IP AFM - addressed in versions 15.1.10.6.0.11.6, 16.1.5.2.0.7.5, 17.1.2