CVE-2025-27810: Medium severity Mbed TLS Mbed TLS vulnerability
Published Mar 25, 2025
·Updated
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Affected Software
3 affected components
Mbed TLS Mbed TLS<2.28.10, <3.6.3
Arm mbed TLS<2.28.10
TrustedFirmware Mbed Tls>=3.0.0<3.6.3
Event History
Mar 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27810?
CVE-2025-27810 is classified as a moderate severity vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2025-27810?
To fix CVE-2025-27810, upgrade to Mbed TLS version 2.28.10 or later, or 3.6.3 or later.
3
What types of issues can CVE-2025-27810 cause?
CVE-2025-27810 can cause authentication bypasses, which may allow for replay attacks.
4
Which versions of Mbed TLS are affected by CVE-2025-27810?
CVE-2025-27810 affects Mbed TLS versions prior to 2.28.10 and 3.x versions prior to 3.6.3.
5
What specific condition triggers CVE-2025-27810?
CVE-2025-27810 is triggered by failed memory allocation or hardware errors during TLS message composition.