ZeroHour

CVE-2020-25648

CVSS 3.1
7.5 high
EPSS
4%p90
Published
()
Modified
Description

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

Vendors
mozillaredhatfedoraprojectoracle
Products
network security services, enterprise linux, fedora, communications offline mediation controller, communications pricing design center, jd edwards enterpriseone tools
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.