CVE-2025-55084: Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check innxsecuretlsprocclienthellosupportedversionsextension() in the extension version field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse Foundation ThreadX (NetX Duo)to a version that resolves this vulnerability.Fixed in 6.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55084?
CVE-2025-55084 is considered a high severity vulnerability due to the potential for unauthorized access and misuse of secure communications.
How do I fix CVE-2025-55084?
To mitigate CVE-2025-55084, upgrade to NetX Duo or Eclipse Foundation ThreadX version 6.4.4 or later.
What are the affected versions for CVE-2025-55084?
CVE-2025-55084 affects all versions of NetX Duo and Eclipse Foundation ThreadX prior to version 6.4.4.
What type of vulnerability is CVE-2025-55084?
CVE-2025-55084 is a correctness vulnerability related to incorrect bound checking in the TLS protocol handling.
Which component is impacted by CVE-2025-55084?
The impacted component in CVE-2025-55084 is the in_nx_secure_tls_proc_clienthello_supported_versions_extension() function in the Eclipse Foundation ThreadX.