CVE-2025-27810

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 908

Summary

CVE-2025-27810 is a vulnerability affecting Mbed TLS before version 2.28.10 and 3.x before 3.6.3. In certain instances of memory allocation failures or hardware errors, the TLS Finished message is constructed using uninitialized stack memory. This issue can result in authentication bypasses through replay attacks. Attackers can exploit this vulnerability to gain unauthorized access to secure communications. System administrators should promptly update their affected Mbed TLS installations to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share