CVE-2025-55083: Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetX Duo (Eclipse Foundation ThreadX)to a version that resolves this vulnerability.Fixed in 6.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55083?
CVE-2025-55083 is classified as a medium severity vulnerability due to its potential to cause out-of-bounds read issues.
How do I fix CVE-2025-55083?
To fix CVE-2025-55083, upgrade your Eclipse Foundation NetX Duo and ThreadX to version 6.4.4 or later.
What systems are affected by CVE-2025-55083?
CVE-2025-55083 affects all versions of Eclipse Foundation NetX Duo and ThreadX prior to 6.4.4.
What type of vulnerability is CVE-2025-55083?
CVE-2025-55083 is a vulnerability related to an incorrect bound check leading to out-of-bounds read access.
Are there any workarounds for CVE-2025-55083?
Currently, the recommended mitigation for CVE-2025-55083 is to update to the latest software version, as no specific workaround has been identified.