Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-27810

Опубликовано: 25 мар. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.4

Описание

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

РелизСтатусПримечание
devel

not-affected

3.6.5-0.1ubuntu2
esm-apps-legacy/xenial

needed

esm-apps/bionic

released

2.8.0-1ubuntu0.1~esm1
esm-apps/focal

released

2.16.4-1ubuntu2+esm1
esm-apps/jammy

released

2.28.0-1ubuntu0.1~esm1
esm-apps/noble

released

2.28.8-1ubuntu0.1~esm1
esm-apps/resolute

not-affected

3.6.5-0.1ubuntu2
esm-apps/xenial

ignored

end of ESM support, was needed
focal

ignored

end of standard support, was needs-triage
jammy

needed

Показывать по

EPSS

Процентиль: 20%
0.00274
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

msrc
12 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

CVSS3: 5.4
debian
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed ...

CVSS3: 5.4
github
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

CVSS3: 5.4
fstec
больше 1 года назад

Уязвимость реализации протокола TLS программного обеспечения Mbed TLS, позволяющая нарушителю проводить атаки типа "человек по середине"

EPSS

Процентиль: 20%
0.00274
Низкий

5.4 Medium

CVSS3