Logo
vulnerabilityCVE-2025-27810
Name
CVE-2025-27810
Source
NVD ( link)Debian ( link)
Description
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis

Vulnerability Ratings#


5.4
CVSSv31
4.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.6.6
Not Affected
buildroot
master
3.6.6
Not Affected
openwrt
master
3.6.7-r1
Not Affected
openwrt
openwrt-25.12
3.6.7-r1
Not Affected
yocto
master
3.6.7
Not Affected
yocto
scarthgap
2.28.10
Not Affected