← Vulnerability feed

Vulnerability record · CVE-2025-41430 · published 15 October 2025

CVE-2025-41430: F5 big-ip ssl orchestrator allocation without limits vulnerability

F5 · Big Ip Ssl Orchestrator

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

8.7 CVSS 4.0 High EPSS 0.35% · top 74.2% CWE-770 · Allocation without limits
8.7CVSS 4.0 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-41430 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed8.8CVE-2023-46748F5 BIG-IP Configuration Utility SQL injection leads to command executionAn authenticated SQL injection flaw exists in the BIG-IP Configuration utility. An attacker who already holds valid credentials and can reach the man…KEVEPSS 4.5%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.9CVE-2023-41373F5 big-ip access policy manager path traversal vulnerabilityA directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BI…EPSS 2.4%8.9CVE-2025-21087F5 big-ip access policy manager uncontrolled resource consumption vulnerabilityWhen Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an incr…EPSS 0.41%8.9CVE-2025-20058F5 big-ip access policy manager uncontrolled resource consumption vulnerabilityWhen a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. No…EPSS 0.41%8.8CVE-2021-23026F5 big-ip access policy manager cross-site request forgery vulnerabilityBIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x an…EPSS 0.48%8.8CVE-2021-23025F5 big-ip access policy manager os command injection vulnerabilityOn version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote com…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2025-41430), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.