ID

VAR-202510-0946


CVE

CVE-2025-53856


TITLE

F5 BIG-IP ePVA Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-25368

DESCRIPTION

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.   To determine which BIG-IP platforms have an ePVA chip refer to K12837: Overview of the ePVA feature https://my.f5.com/manage/s/article/K12837 .   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. F5 BIG-IP is an application delivery platform from F5 that integrates network traffic orchestration, load balancing, intelligent DNS, and remote access policy management. A denial of service vulnerability exists in BIG-IP's ePVA module. An attacker could exploit this vulnerability to cause a denial of service on the BIG-IP system

Trust: 1.44

sources: NVD: CVE-2025-53856 // CNVD: CNVD-2025-25368

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-25368

AFFECTED PRODUCTS

vendor:f5model:big-ip ddos hybrid defenderscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip websafescope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip websafescope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip websafescope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip websafescope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:ltversion:16.1.6.1

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip automation toolchainscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application visibility and reportingscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip carrier-grade natscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip container ingress servicesscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:17.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:17.5.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:17.5.0

Trust: 1.0

vendor:f5model:big-ip advanced web application firewallscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:ltversion:17.1.3

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:15.1.10.8

Trust: 1.0

vendor:f5model:big-ipscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-25368 // NVD: CVE-2025-53856

CVSS

SEVERITY

CVSSV2

CVSSV3

f5sirt@f5.com: CVE-2025-53856
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-25368
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-25368
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

f5sirt@f5.com: CVE-2025-53856
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-25368 // NVD: CVE-2025-53856

PROBLEMTYPE DATA

problemtype:CWE-705

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2025-53856

PATCH

title:Patch for F5 BIG-IP ePVA Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/744116

Trust: 0.6

sources: CNVD: CNVD-2025-25368

EXTERNAL IDS

db:NVDid:CVE-2025-53856

Trust: 1.6

db:CNVDid:CNVD-2025-25368

Trust: 0.6

sources: CNVD: CNVD-2025-25368 // NVD: CVE-2025-53856

REFERENCES

url:https://my.f5.com/manage/s/article/k000156707

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-53856

Trust: 0.6

sources: CNVD: CNVD-2025-25368 // NVD: CVE-2025-53856

SOURCES

db:CNVDid:CNVD-2025-25368
db:NVDid:CVE-2025-53856

LAST UPDATE DATE

2025-11-19T23:14:42.938000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-25368date:2025-10-27T00:00:00
db:NVDid:CVE-2025-53856date:2025-10-21T20:19:02.110

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-25368date:2025-10-21T00:00:00
db:NVDid:CVE-2025-53856date:2025-10-15T14:15:48.600