CVE-2025-27809
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-27809 refers to a vulnerability in Mbed TLS versions before 2.28.10 and 3.x before 3.6.3. This issue, which affects TLS client applications, allows servers with trusted certificates to be accepted for arbitrary hostnames. If exploited, an attacker could potentially conduct man-in-the-middle attacks or perform other malicious activities, undermining the security of SSL/TLS communication channels. To mitigate this risk, Mbed TLS users should update to the latest versions or manually call the mbedtls_ssl_set_hostname function to restrict trusted certificates to specific hostnames.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.