CVE-2025-47148

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization.Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
f5CNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
f5big-ip_access_policy_manager
15.1.0 ≤
𝑥
< 15.1.10.8
f5big-ip_access_policy_manager
16.1.0 ≤
𝑥
< 16.1.6.1
f5big-ip_access_policy_manager
17.1.0 ≤
𝑥
< 17.1.3
f5big-ip_access_policy_manager
17.5.0
f5big-ip_ssl_orchestrator
15.1.0 ≤
𝑥
< 15.1.10.8
f5big-ip_ssl_orchestrator
16.1.0 ≤
𝑥
< 16.1.6.1
f5big-ip_ssl_orchestrator
17.1.0 ≤
𝑥
< 17.1.3
f5big-ip_ssl_orchestrator
17.5.0
𝑥
= Vulnerable software versions