← Back

CVE-2025-27809

nvd nist
Published: Mar 25, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.7
Source: MITRE (Secondary)

Description

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

Affected (2)

1 product
Mbed Tls
Mbed Tls
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.28.10
From 3.0.0 to 3.6.3

References (4)

Source: cve@mitre.org
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.