VulnerabilityAnalyzed
CVE-2025-27809
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
MEDIUM 5.4EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1188
- Affected
- arm/mbed tls · trustedfirmware/mbed tls
- Source
- cve@mitre.org
References
- https://github.com/Mbed-TLS/mbedtls/releasesRelease Notes
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-03-1/Third Party Advisory
- https://github.com/Mbed-TLS/mbedtls/issues/466Issue Tracking
- https://mastodon.social/@bagder/114219540623402700Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.