CERT-In Flags Critical F5 Security Flaws
ID: 297d56f7-156b-5f66-bc31-c497ec8396b3
STIX ID: report--297d56f7-156b-5f66-bc31-c497ec8396b3
Feed Name: Cyble Blog
CERT-In advisory CIVN-2025-0035 details multiple vulnerabilities affecting a broad range of F5 products (BIG-IP Next, BIG-IP 15/16/17, BIG-IQ, F5 Distributed Cloud, F5 Silverline, NGINX, Traffix, and hardware models), including CVEs in zlib, Apache Tomcat, MiniZip, and tcpdump that can enable denial-of-service, session hijacking, buffer overflows, and potential arbitrary code execution; F5 recommends mitigations such as disabling HTTP compression, restricting configuration access, upgrading affected components, and applying security patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
