icon

We found results for “

CVE-2025-55081

Good to know:

icon

Date: October 15, 2025

In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and compression method length. In case of an attacker-crafted message with values outside of the expected range, it could cause an out-of-bound read.

Severity Score

Severity Score

Weakness Type (CWE)

Out-of-bounds Read

CWE-125

Buffer Over-read

CWE-126

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/eclipse-threadx/netxduo.git - v.6.4.4.202503_rel

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us