TROYANOSYVIRUS
Volver a CVEs

CVE-2025-27810

MEDIUM
5.4

Descripcion

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

Detalles CVE

Puntuacion CVSS v3.15.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/25/2025
Ultima modificacion10/30/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

arm:mbed_tls

Debilidades (CWE)

CWE-908

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.