Executive Summary
In June 2024, a critical vulnerability affecting F5 devices exposed a major blind spot within the Department of Homeland Security's Continuous Diagnostics and Mitigation (CDM) program, which is tasked with overseeing federal cybersecurity assets. The Cybersecurity and Infrastructure Security Agency (CISA) was forced to issue an emergency directive after learning that a nation-state actor had exploited F5 edge devices to gain persistent access across multiple civilian federal agencies. The directive revealed that while thousands of F5 systems were in use, there was significant uncertainty about their location due to gaps in federal asset inventory capabilities, particularly for internet-facing edge devices like F5 BIG-IP load balancers. As a result, agencies had to scramble to manually identify and secure affected systems, highlighting the operational impact of incomplete visibility and asset management.
The incident underscores the growing risks associated with network edge devices, which have become prime targets for sophisticated attackers exploiting gaps outside traditional IT inventories. As cloud adoption and edge architectures proliferate, ensuring asset visibility and securing non-traditional endpoints have become urgent priorities for government and private sector organizations alike, as attackers increasingly exploit these visibility gaps.
Why This Matters Now
This incident highlights urgent gaps in the federal government’s asset visibility and response readiness, especially as agencies accelerate cloud and edge technology adoption. With threat actors targeting unmonitored edge devices, organizations must evolve beyond traditional IT inventories and improve real-time detection and response across all network layers.
Attack Path Analysis
Attackers first exploited a vulnerability in internet-exposed F5 edge devices lacking adequate visibility or monitoring (Initial Compromise). They then escalated privileges through exploiting the device to gain deeper access or persistent control (Privilege Escalation). With access, attackers moved laterally within the network, leveraging the F5's privileged position between DMZ and internal environments (Lateral Movement). They established command and control channels to maintain persistence and direct further activity (Command & Control). Sensitive data was then exfiltrated via covert or permitted network flows (Exfiltration). Finally, attackers could impact agency operations through data manipulation or prolonged disruption (Impact).
Kill Chain Progression
Initial Compromise
Description
Attackers exploited an unpatched vulnerability in public-facing F5 BIG-IP edge devices to gain an initial foothold into the agency network.
Related CVEs
CVE-2025-46265
CVSS 8.7An improper authorization vulnerability in F5OS allows remotely authenticated users to gain higher privilege roles.
Affected Products:
F5 Networks F5OS – All versions prior to the fix
Exploit Status:
no public exploitCVE-2025-60015
CVSS 6.9An out-of-bounds write vulnerability in F5OS-A and F5OS-C could lead to memory corruption.
Affected Products:
F5 Networks F5OS-A – All versions prior to the fix
F5 Networks F5OS-C – All versions prior to the fix
Exploit Status:
no public exploitCVE-2025-61955
CVSS 8.5A vulnerability in F5OS-A and F5OS-C may allow an authenticated attacker with local access to escalate their privileges.
Affected Products:
F5 Networks F5OS-A – All versions prior to the fix
F5 Networks F5OS-C – All versions prior to the fix
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
External Remote Services
Exploit Public-Facing Application
Valid Accounts
Network Service Discovery
Account Discovery
Automated Exfiltration
Exploitation of Remote Services
Impair Defenses
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Define and Maintain Secure Asset Inventories
Control ID: 8.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
DORA (EU Digital Operational Resilience Act) – Identification and Documentation of ICT Assets
Control ID: Article 10
CISA Zero Trust Maturity Model 2.0 – Comprehensive Asset Visibility Across Environments
Control ID: Asset Management (Visibility)
NIS2 Directive – Asset Management and Security Risk Management
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
F5 infrastructure vulnerabilities expose federal agencies to nation-state attacks, highlighting CDM program gaps in edge device visibility and asset management capabilities.
Financial Services
Edge device blind spots in load balancers and network infrastructure create exposure to lateral movement and data exfiltration risks affecting compliance frameworks.
Health Care / Life Sciences
Network segmentation weaknesses and east-west traffic visibility gaps compromise HIPAA compliance requirements for encrypted data protection and access controls.
Telecommunications
Critical network infrastructure dependencies on F5 edge devices create nation-state attack vectors compromising encrypted traffic and multicloud connectivity security controls.
Sources
- F5 vulnerability highlights weak points in DHS’s CDM programhttps://cyberscoop.com/f5-vulnerability-highlights-weak-points-in-dhss-cdm-program/Verified
- F5 Networks Security Advisory K000139503https://my.f5.com/manage/s/article/K000139503Verified
- NVD - CVE-2025-46265https://nvd.nist.gov/vuln/detail/CVE-2025-46265Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing CNSF capabilities like network segmentation, east-west traffic security, egress filtering, threat detection, and real-time cloud-native enforcement would have significantly limited attacker movement, improved asset visibility, and detected suspicious activity—directly constraining key stages of this attack.
Control: Cloud Firewall (ACF)
Mitigation: Cloud perimeter traffic inspection blocks exploits targeting known vulnerabilities.
Control: Threat Detection & Anomaly Response
Mitigation: Real-time alerting on privilege abuse or anomalous administrative activities.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation blocks unauthorized lateral movement from edge devices.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks known C2 traffic and malicious outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data exfiltration is detected or blocked through FQDN and protocol filtering.
Continuous visibility enables rapid detection and response to abnormal asset or network changes.
Impact at a Glance
Affected Business Functions
- Network Operations
- Security Monitoring
Estimated downtime: 3 days
Estimated loss: $500,000
Potential unauthorized access to sensitive government data due to elevated privileges gained through the vulnerability.
Recommended Actions
Key Takeaways & Next Steps
- • Expand continuous inventory and visibility over all edge devices and cloud workloads, leveraging Multicloud Visibility & Control tools.
- • Enforce Zero Trust Segmentation and microsegmentation to restrict east-west and DMZ-to-internal lateral movement.
- • Deploy Cloud Firewall (ACF) and Inline IPS at ingress and egress to detect exploits and suspicious C2 or data exfiltration.
- • Implement robust Egress Security & Policy Enforcement to block unauthorized outbound traffic and prevent data loss.
- • Regularly baseline privilege escalation and administrative actions using Threat Detection & Anomaly Response to rapidly detect and contain future attacks.



