Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://my.f5.com/manage/s/article/K000156621 |
|
Tue, 21 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5 big-ip Advanced Web Application Firewall
F5 big-ip Application Security Manager |
|
| CPEs | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
F5 big-ip Advanced Web Application Firewall
F5 big-ip Application Security Manager |
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5
F5 big-ip |
|
| Vendors & Products |
F5
F5 big-ip |
Wed, 15 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | BIG-IP Advanced WAF and ASM vulnerability | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2025-10-16T03:56:55.858Z
Reserved: 2025-10-03T23:04:38.066Z
Link: CVE-2025-54858
Updated: 2025-10-15T15:33:02.570Z
Status : Analyzed
Published: 2025-10-15T14:15:50.343
Modified: 2025-10-21T20:13:30.940
Link: CVE-2025-54858
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:26:39Z