CVE-2025-3200

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 327

Summary

CVE-2025-3200 is a newly disclosed vulnerability that enables unauthenticated attackers to interfere with encrypted communications between a Com-Server and connected systems. The weakness lies in the use of insecure TLS 1.0 and TLS 1.1 protocols, which are susceptible to man-in-the-middle attacks. By exploiting this vulnerability, adversaries can potentially eavesdrop on data transmissions, modify information, or inject malicious code. To mitigate this risk, it is essential to update the Com-Server software and disable support for TLS 1.0 and TLS 1.1 in favor of more secure alternatives.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share