Executive brief
A vulnerability exists in the F5 BIG-IP Configuration utility when it is configured to use LDAP for authentication. An attacker can send specific network traffic that causes the system to run out of internal resources (file descriptors), leading to a denial-of-service. This can prevent administrators from managing the device and may impact the availability of the services it provides.
Technical details
This vulnerability is classified as a Missing Release of Resource after Effective Lifetime (CWE-772) within the BIG-IP Configuration utility. When LDAP authentication is enabled, the httpd process fails to properly manage file descriptors when processing specific, undisclosed network traffic. A remote, unauthenticated attacker can exploit this to exhaust the available file descriptors, resulting in a denial-of-service (DoS) of the management interface. The vulnerability has a CVSS 3.1 score of 7.5 and a CVSS 4.0 score of 8.7. F5 has not evaluated software versions that have reached End of Technical Support (EoTS).
Affected products
- F5 BIG-IP All versions prior to End of Technical Support (EoTS)
Timeline
- 2026-05-13: advisory: Initial advisory published by F5 and NVD