Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-27809

Опубликовано: 25 мар. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.4

Описание

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

РелизСтатусПримечание
devel

not-affected

3.6.5-0.1ubuntu2
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

ignored

changes too intrusive
esm-apps/jammy

ignored

changes too intrusive
esm-apps/noble

ignored

changes too intrusive
esm-apps/xenial

ignored

changes too intrusive
focal

ignored

end of standard support, was needs-triage
jammy

ignored

changes too intrusive
noble

ignored

changes too intrusive
oracular

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 24%
0.00081
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

msrc
7 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

CVSS3: 5.4
debian
около 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, acce ...

CVSS3: 5.4
github
около 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

CVSS3: 5.4
fstec
около 1 года назад

Уязвимость функции mbedtls_ssl_set_hostname программного обеспечения Mbed TLS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 24%
0.00081
Низкий

5.4 Medium

CVSS3