CVE-2025-27809: Medium severity Arm mbed TLS vulnerability
Published Mar 25, 2025
·Updated
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtlssslsethostname.
Affected Software
3 affected components
Arm mbed TLS<2.28.10, <3.6.3
Arm mbed TLS<2.28.10
TrustedFirmware Mbed Tls>=3.0.0<3.6.3
Event History
Mar 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27809?
CVE-2025-27809 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2025-27809?
To fix CVE-2025-27809, ensure that the mbedtls_ssl_set_hostname function is called in your TLS client application.
3
Which versions of Mbed TLS are affected by CVE-2025-27809?
CVE-2025-27809 affects Mbed TLS versions before 2.28.10 and 3.x before 3.6.3.
4
What impact does CVE-2025-27809 have on TLS connections?
CVE-2025-27809 allows TLS clients to trust servers based on arbitrary hostnames, which can lead to security risks.
5
Is there a patch available for CVE-2025-27809?
Yes, patches for CVE-2025-27809 are available in Mbed TLS versions 2.28.10 and 3.6.3 and later.