#VU108777 Input validation error in BIG-IP PEM - CVE-2025-35995
Published: May 7, 2025
BIG-IP PEM
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server. A remote attacker can send specially crafted input to the system and perform a denial of service (DoS) attack.