Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13937 | When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| Link | Providers |
|---|---|
| https://my.f5.com/manage/s/article/K000149952 |
|
Mon, 18 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5 big-ip Policy Enforcement Manager
|
|
| CPEs | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
F5 big-ip Policy Enforcement Manager
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | BIG-IP PEM vulnerability | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2025-05-08T13:04:34.901Z
Reserved: 2025-04-23T22:28:26.371Z
Link: CVE-2025-35995
Updated: 2025-05-08T13:04:31.786Z
Status : Analyzed
Published: 2025-05-07T22:15:19.470
Modified: 2025-09-29T21:30:36.247
Link: CVE-2025-35995
No data.
OpenCVE Enrichment
Updated: 2025-07-15T08:04:37Z
EUVD