CVE-2025-15615: Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wazuh Manager authd service (wazuh-manager packages)to a version that resolves this vulnerability.Fixed in 4.7.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15615?
CVE-2025-15615 is classified as a denial of service vulnerability with a moderate severity rating.
How do I fix CVE-2025-15615?
To fix CVE-2025-15615, upgrade Wazuh Manager to version 4.7.4 or later to mitigate the proper restriction of client-initiated SSL/TLS renegotiation.
What versions are affected by CVE-2025-15615?
CVE-2025-15615 affects Wazuh Manager versions up to and including 4.7.3.
What type of vulnerability is CVE-2025-15615?
CVE-2025-15615 is a vulnerability related to improper restriction of client-initiated SSL/TLS renegotiation.
Can CVE-2025-15615 be exploited remotely?
Yes, CVE-2025-15615 can be exploited remotely by attackers to cause a denial of service.