THE SUMMARYAI-generated
Key Concepts:
- Quarterly Security Notifications (QSNs)
- CVE (Common Vulnerabilities and Exposures)
- BIG-IP, BIG-IP Next (SPK, CNF, for Kubernetes)
- NGINX Open Source, NGINX Plus
- APM Edge Client (macOS)
- F5 Access Client (Android)
- F5 Silverline
- CVSS (Common Vulnerability Scoring System)
- Control Plane vs. Data Plane
- Engineering Hotfix (EHF)
- HTTP/2, HTTP/1.1
- SMTP (Simple Mail Transfer Protocol)
- Denial of Service (DoS)
- Local Privilege Escalation
- Man-in-the-Middle Attack
1. Introduction and Purpose of Quarterly Security Notifications (QSNs)
- F5 shifted from ad hoc CVE releases to quarterly security notifications (QSNs) in November 2021 to simplify mitigation steps for customers and minimize outages.
- Dev Central collaborates with F5's security incident response team to provide up-to-date information.
- Customers are advised to check security advisories for details and recommended mitigations and to run the most current code versions.
- QSNs align public communication of vulnerabilities across F5 offerings on a single date each quarter.
- Vulnerability disclosure and remediation are key to F5's security practices.
2. August 2025 QSN Overview
- The August 2025 QSN was presented by Chris Palmer from the F5 security incident response team.
- Disclosure date: 7:00 AM Pacific Time.
- Six issues were addressed in this QSN.
- No critical severity vulnerabilities were identified.
- Three vulnerabilities were reported by external researchers.
- Affected products include:
- BIG-IP
- BIG-IP Next, BIG-IP Next SPK, BIG-IP Next CNF, and BIG-IP Next for Kubernetes
- NGINX Open Source and NGINX Plus
- BIG-IP APM Edge Client for macOS
- F5 Access Client for Android
- F5 Silverline
- The next QSN is scheduled for October 15, 2025.
3. Severity and Product Breakdown
- CVSS 3.1 Severity:
- Critical: 0
- High: 4
- Medium: 1
- Low: 1
- Product Impact:
- BIG-IP: 4
- BIG-IP Next: 1
- BIG-IP Next SPK, CNF, and for Kubernetes: 1
- APM Edge Client: 1
- F5 Access Client: 1
- F5 Silverline: 1
- NGINX Open Source: 1
- NGINX Plus: 1
- Type Breakdown:
- Control Plane: 0
- Data Plane: 4
- Edge Client: 1
- F5 Access: 1
- Note: Counts do not add up to the total because each issue can impact multiple products and have multiple scores.
4. Minimum Versions for Fixes
- BIG-IP: 17.1.5.1, 17.1.2.2, 16.1.6
- BIG-IP Next: 20.3.0
- BIG-IP Next SPK, CNF, and for Kubernetes: 2.0.0
- APM Edge Client: 7.2.5.3
- F5 Access Client: 3.1.2
- NGINX Open Source: 1.29.1
- NGINX Plus: R32P3, R33P3, R34P2, and R35
- An Engineering Hotfix (EHF) is required for at least one CVE in this disclosure. EHFs are available on MyF5 for BIG-IP 17.1, 17.1.5 and 16.1. For other products requiring an EHF, a support case needs to be opened.
5. Spotlight on Researcher-Reported Issues
- CVE-2025-54500: HTTP2 Made You Reset Attack (Medium Severity, CVSS 5.3)
- Multi-vendor announcement coordinated through Vents.
- Denial of Service (DoS) vulnerability.
- Malformed HTTP/2 control frames break the max concurrent stream limit.
- Mitigation: Disable HTTP/2 and use HTTP/1.1.
- Fix available via Engineering Hotfix (EHF). EHFs are currently available on MyF5 for BIG-IP 17.1, 17.1.5 and 16.1. For others, open a support request.
- CVE-2025-48500: BIG-IP APM macOS Web Client Local Privilege Escalation (High Severity, CVSS 7.3)
- Impacts BIG-IP APM macOS web client.
- A local authenticated attacker can bypass endpoint inspection checks for files, leading to local privilege escalation.
- Mitigation: Use the BIG-IP Edge Client for Mac VPN instead of the browser-based VPN.
- CVE-2025-53859: NGINX Open Source and NGINX Plus Arbitrary Byte Leak (Low Severity, CVSS 3.7)
- Impacts NGINX Open Source and NGINX Plus.
- A remote unauthenticated attacker can cause a leak of arbitrary bytes during NGINX SMTP authentication.
- The SMTP module is not included by default in NGINX Open Source but is included in NGINX Plus.
- Mitigation: Remove the use of the "none" method in the SMTP directive in the NGINX configuration.
- The leak is triggered on the client side, but the leaked bytes are seen on the server side, complicating exploitation.
6. Q&A and Discussion
- The QSN was considered fairly "gentle."
- The HTTP/2 vulnerability was highlighted as the most concerning, requiring a hotfix.
- The BIG-IP APM macOS vulnerability requires an authenticated attacker with ownership of the client machine.
- The NGINX vulnerability requires a man-in-the-middle position to capture leaked arbitrary bytes, making exploitation complex due to the randomness of the leaked data.
- Upgrading to the latest software versions is recommended.
7. Customer Support and Contact Information
- Customers with issues should open a support case with F5.
- Community members can seek assistance on community.f5.com (Dev Central).
8. Conclusion
- The August 2025 Quarterly Security Notification addressed six issues, with no critical vulnerabilities. The most significant issue was the HTTP/2 vulnerability, requiring an EHF. Customers are advised to review the advisories, apply necessary patches or mitigations, and keep their systems up to date. The next QSN is scheduled for October 15, 2025.
AI summaries can miss context or contain errors. Check important details against the original video.
MAKE IT YOURS
Free tools




