CVE Vulnerabilities

CVE-2025-55248

Inadequate Encryption Strength

Published: Oct 14, 2025 | Modified: Oct 23, 2025
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
.net_frameworkMicrosoft4.6.2 (including)4.6.2 (including)
.net_frameworkMicrosoft4.7 (including)4.7 (including)
.net_frameworkMicrosoft4.7.1 (including)4.7.1 (including)
.net_frameworkMicrosoft4.7.2 (including)4.7.2 (including)
Red Hat Enterprise Linux 10RedHatdotnet8.0-0:8.0.121-1.el10_0*
Red Hat Enterprise Linux 10RedHatdotnet9.0-0:9.0.111-1.el10_0*
Red Hat Enterprise Linux 8RedHatdotnet8.0-0:8.0.121-1.el8_10*
Red Hat Enterprise Linux 8RedHatdotnet9.0-0:9.0.111-1.el8_10*
Red Hat Enterprise Linux 9RedHatdotnet8.0-0:8.0.121-1.el9_6*
Red Hat Enterprise Linux 9RedHatdotnet9.0-0:9.0.111-1.el9_6*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatdotnet8.0-0:8.0.121-1.el9_4*
Red Hat OpenShift Dev Spaces (RHOSDS) 3.25RedHatdevspaces/udi-rhel9:sha256:ef84715a61474b7a45b0b24c0d30370f51ab93ff86b70d5d345545253e01c3ae*
Dotnet10Ubuntuplucky*
Dotnet7Ubuntujammy*
Dotnet8Ubuntujammy*
Dotnet8Ubuntunoble*
Dotnet8Ubuntuplucky*
Dotnet8Ubuntuquesting*
Dotnet9Ubuntuplucky*
Dotnet9Ubuntuquesting*

Potential Mitigations

References