Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-12888

Опубликовано: 21 нояб. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wolfssl:wolfssl:5.8.2:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00017
Низкий

7.5 High

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.

msrc
2 месяца назад

Constant Time Issue with Xtensa-based ESP32 and X22519

CVSS3: 7.5
debian
3 месяца назад

Vulnerability in X25519 constant-time cryptographic implementations du ...

CVSS3: 7.5
github
3 месяца назад

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.

EPSS

Процентиль: 3%
0.00017
Низкий

7.5 High

CVSS3

Дефекты

CWE-203