Vulnerability Details CVE-2025-58474
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.5%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2025-58474
-
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.0
-
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.0.1
-
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.0.2
-
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.1
-
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.1.3
-
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.1.4
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0.2
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0.3
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.1.3
-
cpe:2.3:a:f5:big-ip_application_security_manager:17.1.1.4