CVE-2025-27809
5.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.7
Source: MITRE (Secondary)
Description
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
Affected (2)
Products: Arm: Mbed Tls · Trustedfirmware: Mbed Tls
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.28.10 | |
| From 3.0.0 to 3.6.3 |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Timeline
No history available yet.