Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-15615

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 5.8
CVSS3: 7.5
EPSS Низкий

Описание

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*
Версия до 4.8.0 (исключая)

EPSS

Процентиль: 42%
0.00497
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.8
github
6 месяцев назад

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.

EPSS

Процентиль: 42%
0.00497
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-276