Executive brief
F5 BIG-IP devices, which manage and secure enterprise network traffic, are vulnerable to a denial-of-service attack when processing specific Session Initiation Protocol (SIP) traffic. An attacker can send specially crafted network traffic to a virtual server, causing the core traffic management component to crash. This results in a complete interruption of network services and application availability managed by the affected BIG-IP system.
Technical details
This vulnerability is classified as a resource management issue (CWE-770) within the Traffic Management Microkernel (TMM) of F5 BIG-IP. When a virtual server is configured with a SIP (Session Initiation Protocol) profile, it fails to properly handle specific, undisclosed network traffic. A remote, unauthenticated attacker can exploit this by sending malicious SIP packets, leading to a TMM crash and subsequent denial of service. The vulnerability affects multiple BIG-IP modules including LTM, AFM, and APM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released a vendor advisory (K000161023) detailing affected versions and potential mitigations.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Application Security Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory.