CVE-2025-22891

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
05/02/2025
Last modified:
06/08/2025

Description

When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* 15.1.0 (including) 15.1.10.6.0.11.6 (excluding)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.5 (excluding)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* 17.1.0 (including) 17.1.2 (excluding)


References to Advisories, Solutions, and Tools