← Back

CVE-2025-27810

nvd nist
Published: Mar 25, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD

Description

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

Affected (2)

1 product
Mbed Tls
Mbed Tls
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.28.10
From 3.0.0 to 3.6.3

Timeline

No history available yet.