Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27810

Опубликовано: 25 мар. 2025
Источник: nvd
CVSS3: 5.4
CVSS3: 4.8
EPSS Низкий

Описание

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
Версия до 2.28.10 (исключая)
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.6.3 (исключая)

EPSS

Процентиль: 23%
0.00074
Низкий

5.4 Medium

CVSS3

4.8 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.4
ubuntu
9 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

msrc
3 месяца назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

CVSS3: 5.4
debian
9 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed ...

CVSS3: 5.4
github
9 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

CVSS3: 5.4
fstec
9 месяцев назад

Уязвимость реализации протокола TLS программного обеспечения Mbed TLS, позволяющая нарушителю проводить атаки типа "человек по середине"

EPSS

Процентиль: 23%
0.00074
Низкий

5.4 Medium

CVSS3

4.8 Medium

CVSS3

Дефекты

CWE-908