← Vulnerability feed

Vulnerability record · CVE-2025-59778 · published 15 October 2025

CVE-2025-59778: F5os-c allocation without limits vulnerability

F5 · F5os C

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

7.7 CVSS 4.0 High EPSS 0.34% · top 75.7% CWE-770 · Allocation without limits
7.7CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59778 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2025-36546F5os-a incorrect authorization vulnerabilityOn an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance …EPSS 0.42%8.8CVE-2022-41835F5os-a improper privilege management vulnerabilityIn F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to …EPSS 0.15%8.7CVE-2025-46265F5os-a incorrect authorization vulnerabilityOn F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher priv…EPSS 0.37%8.5CVE-2025-57780F5os-a execution with unnecessary privileges vulnerabilityA vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A succes…EPSS 0.21%8.5CVE-2025-61955F5os-a vulnerabilityA vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A succe…EPSS 0.25%8.3CVE-2025-43878F5os-a vulnerabilityWhen running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance m…EPSS 0.17%7.8CVE-2023-22657F5os-a command injection vulnerabilityOn F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may all…EPSS 0.44%7.5CVE-2002-20001Balasys dheater uncontrolled resource consumption vulnerabilityThe Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys,…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2025-59778), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.