ZeroHour

CVE-2025-27809

CVSS 3.1
5.4 medium
EPSS
<1%p9
Published
()
Modified
Description

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

Vendors
armtrustedfirmware
Products
mbed tls
Weakness
CWE-1188
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.