CVE-2025-53856

HIGH

BIG-IP - DoS

Title source: llm
STIX 2.1

Description

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  To determine which BIG-IP platforms have an ePVA chip refer to K12837: Overview of the ePVA feature https://my.f5.com/manage/s/article/K12837 .  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 10.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-705
Status published
Products (21)
f5/big-ip_access_policy_manager 15.1.0 - 15.1.10.8
f5/big-ip_advanced_firewall_manager 15.1.0 - 15.1.10.8
f5/big-ip_advanced_web_application_firewall 15.1.0 - 15.1.10.8
f5/big-ip_analytics 15.1.0 - 15.1.10.8
f5/big-ip_application_acceleration_manager 15.1.0 - 15.1.10.8
f5/big-ip_application_security_manager 15.1.0 - 15.1.10.8
f5/big-ip_application_visibility_and_reporting 15.1.0 - 15.1.10.8
f5/big-ip_automation_toolchain 15.1.0 - 15.1.10.8
f5/big-ip_carrier-grade_nat 15.1.0 - 15.1.10.8
f5/big-ip_container_ingress_services 15.1.0 - 15.1.10.8
... and 11 more
Published Oct 15, 2025
Tracked Since Feb 18, 2026