VDB

CVE-2025-27810

CVE-2025-27810 PUBLISHED CVSS 5.400000095367432 MEDIUM

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

EPSS 0.29% · 19.8th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS Score
0.29%
19.8th percentile

Affected Products

VendorProductVersions
armmbed_tls3.0.0, 0
mbedmbedtls0, 3.0.0
Mbedmbedtls0, 3.0.0

Timeline

  • Mar 25, 2025 CVE Published
  • Mar 25, 2025 EPSS Score
  • Mar 25, 2025 Coalition ESS Score
  • Mar 25, 2025 PoC Published
  • Mar 28, 2025 Coalition ESS Score
  • Apr 8, 2025 EPSS Score
  • Apr 21, 2025 EPSS Score
  • May 5, 2025 EPSS Score
  • May 18, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
  • Jun 15, 2025 EPSS Score
  • Jun 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›