Логотип exploitDog
bind:CVE-2025-11935
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-11935

Количество 5

Количество 5

ubuntu логотип

CVE-2025-11935

3 месяца назад

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-11935

3 месяца назад

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-11935

3 месяца назад

Forward Secrecy Violation in WolfSSL TLS 1.3

EPSS: Низкий
debian логотип

CVE-2025-11935

3 месяца назад

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could i ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4497-xvm3-5vh9

3 месяца назад

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-11935

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-11935

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-11935

Forward Secrecy Violation in WolfSSL TLS 1.3

0%
Низкий
3 месяца назад
debian логотип
CVE-2025-11935

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could i ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4497-xvm3-5vh9

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу