CVE Vulnerabilities

CVE-2025-27809

Initialization of a Resource with an Insecure Default

Published: Mar 25, 2025 | Modified: Jul 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

Weakness

The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.

Affected Software

NameVendorStart VersionEnd Version
Mbed_tlsArm*2.28.10 (excluding)
Mbed_tlsArm3.0.0 (including)3.6.3 (excluding)
MbedtlsUbuntudevel*
MbedtlsUbuntuesm-apps/bionic*
MbedtlsUbuntuesm-apps/focal*
MbedtlsUbuntuesm-apps/jammy*
MbedtlsUbuntuesm-apps/noble*
MbedtlsUbuntuesm-apps/xenial*
MbedtlsUbuntufocal*
MbedtlsUbuntujammy*
MbedtlsUbuntunoble*
MbedtlsUbuntuoracular*
MbedtlsUbuntuplucky*
MbedtlsUbuntuquesting*
MbedtlsUbuntuupstream*

References