CVE-2025-27809

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 1188

Summary

CVE-2025-27809 refers to a vulnerability in Mbed TLS versions before 2.28.10 and 3.x before 3.6.3. This issue, which affects TLS client applications, allows servers with trusted certificates to be accepted for arbitrary hostnames. If exploited, an attacker could potentially conduct man-in-the-middle attacks or perform other malicious activities, undermining the security of SSL/TLS communication channels. To mitigate this risk, Mbed TLS users should update to the latest versions or manually call the mbedtls_ssl_set_hostname function to restrict trusted certificates to specific hostnames.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share