F5 BIG-IP SSL/TLS Denial-of-Service Vulnerability via ECC Brainpool Diffie-Hellman Groups

Vulnerability

A denial-of-service vulnerability has been identified in F5 BIG-IP systems when Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are used in an SSL profile's Cipher Rule or Cipher Group. This issue affects both Client SSL and Server SSL profiles, disrupting traffic by causing the Traffic Management Microkernel (TMM) to crash and restart. The vulnerability can be exploited by remote, unauthenticated attackers, but only when the affected SSL profile is applied to a virtual server.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition on the BIG-IP system, causing traffic disruption while the TMM process restarts.

Remediation

To address this vulnerability, remove ECC Brainpool curves from the DH Groups setting of the affected Cipher Rule or Cipher Group. This can be done through the BIG-IP Configuration utility or the TMOS Shell (tmsh) command. After making the change, save the configuration and verify that the ECC Brainpool curves have been removed.

Added: Oct 15, 2025, 2:21 PM
Updated: Oct 15, 2025, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
7.6
remediation
7.9
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.