CVE Vulnerabilities

CVE-2025-55248

Inadequate Encryption Strength

Published: Oct 14, 2025 | Modified: Oct 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Dotnet7 Ubuntu jammy *
Dotnet8 Ubuntu jammy *
Dotnet8 Ubuntu noble *
Dotnet8 Ubuntu plucky *
Dotnet8 Ubuntu questing *
Dotnet9 Ubuntu plucky *
Dotnet9 Ubuntu questing *

Potential Mitigations

References