CVE Vulnerabilities

CVE-2025-55248

Inadequate Encryption Strength

Published: Oct 14, 2025 | Modified: Oct 23, 2025
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Ubuntu
MEDIUM

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
.net_framework Microsoft 4.6.2 (including) 4.6.2 (including)
.net_framework Microsoft 4.7 (including) 4.7 (including)
.net_framework Microsoft 4.7.1 (including) 4.7.1 (including)
.net_framework Microsoft 4.7.2 (including) 4.7.2 (including)
Red Hat Enterprise Linux 10 RedHat dotnet8.0-0:8.0.121-1.el10_0 *
Red Hat Enterprise Linux 10 RedHat dotnet9.0-0:9.0.111-1.el10_0 *
Red Hat Enterprise Linux 8 RedHat dotnet8.0-0:8.0.121-1.el8_10 *
Red Hat Enterprise Linux 8 RedHat dotnet9.0-0:9.0.111-1.el8_10 *
Red Hat Enterprise Linux 9 RedHat dotnet8.0-0:8.0.121-1.el9_6 *
Red Hat Enterprise Linux 9 RedHat dotnet9.0-0:9.0.111-1.el9_6 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat dotnet8.0-0:8.0.121-1.el9_4 *
Dotnet7 Ubuntu jammy *
Dotnet8 Ubuntu jammy *
Dotnet8 Ubuntu noble *
Dotnet8 Ubuntu plucky *
Dotnet8 Ubuntu questing *
Dotnet9 Ubuntu plucky *
Dotnet9 Ubuntu questing *

Potential Mitigations

References