Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25648

Опубликовано: 19 окт. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability.

Отчет

This flaw only affects servers that are compiled with the NSS library and when the TLS 1.3 protocol is used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nssOut of support scope
Red Hat Enterprise Linux 6nssOut of support scope
Red Hat Enterprise Linux 7nssFixedRHSA-2021:138427.04.2021
Red Hat Enterprise Linux 8nsprFixedRHSA-2021:357221.09.2021
Red Hat Enterprise Linux 8nssFixedRHSA-2021:357221.09.2021
Red Hat Migration Toolkit for Containers 1.4rhmtc/openshift-migration-controller-rhel8FixedRHBA-2021:285421.07.2021
Red Hat Migration Toolkit for Containers 1.4rhmtc/openshift-migration-log-reader-rhel8FixedRHBA-2021:285421.07.2021
Red Hat Migration Toolkit for Containers 1.4rhmtc/openshift-migration-must-gather-rhel8FixedRHBA-2021:285421.07.2021
Red Hat Migration Toolkit for Containers 1.4rhmtc/openshift-migration-operator-bundleFixedRHBA-2021:285421.07.2021
Red Hat Migration Toolkit for Containers 1.4rhmtc/openshift-migration-registry-rhel8FixedRHBA-2021:285421.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1887319nss: TLS 1.3 CCS flood remote DoS Attack

EPSS

Процентиль: 32%
0.00123
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

CVSS3: 7.5
nvd
почти 5 лет назад

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

CVSS3: 7.5
debian
почти 5 лет назад

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) message ...

rocky
почти 4 года назад

Moderate: nss and nspr security, bug fix, and enhancement update

CVSS3: 7.5
github
около 3 лет назад

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

EPSS

Процентиль: 32%
0.00123
Низкий

7.5 High

CVSS3