Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvqm-mmw4-qwg5

Опубликовано: 25 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

EPSS

Процентиль: 20%
0.00274
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

CVSS3: 5.4
nvd
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

msrc
12 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

CVSS3: 5.4
debian
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed ...

CVSS3: 5.4
fstec
больше 1 года назад

Уязвимость реализации протокола TLS программного обеспечения Mbed TLS, позволяющая нарушителю проводить атаки типа "человек по середине"

EPSS

Процентиль: 20%
0.00274
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-908