Wiz Agents & Workflows are here

CVE-2025-27810
Mbed TLS vulnerability analysis and mitigation

Overview

CVE-2025-27810 affects Mbed TLS versions before 2.28.10 and 3.x before 3.6.3. The vulnerability involves the TLS Finished message calculation, where in cases of failed memory allocation or hardware errors, the system uses uninitialized stack memory to compose the TLS Finished message. This vulnerability was discovered and disclosed on March 24, 2025 (MITRE, NVD).

Technical details

The vulnerability occurs during the TLS handshake process, specifically in the calculation of the Finished message which is crucial for ensuring handshake integrity. When memory allocation fails or a cryptographic hardware driver returns an error at a specific point during the handshake, the system incorrectly uses uninitialized stack memory content for the Finished message calculation. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.4 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N (NVD).

Impact

The vulnerability could potentially lead to authentication bypasses such as replay attacks. An attacker with the ability to trigger memory allocation failures or cryptographic hardware failures may be able to break the security guarantees of the TLS handshake. This could enable them to tamper with the handshake through a Man in the Middle attack or replay handshake messages to impersonate a legitimate peer (Security Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade to Mbed TLS version 2.28.10 or 3.6.3, which contain fixes for this vulnerability. As a workaround, users can ensure that sufficient memory is available before performing a handshake and verify that any cryptographic hardware drivers used for hash functions cannot return errors (Security Advisory).

Additional resources


SourceThis report was generated using AI

Related Mbed TLS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-47917CRITICAL9.8
  • Mbed TLSMbed TLS
  • dolphin-emu
NoYesJul 20, 2025
CVE-2025-48965HIGH7.5
  • Mbed TLSMbed TLS
  • dolphin-emu-debuginfo
NoYesJul 20, 2025
CVE-2025-54764MEDIUM6.2
  • Mbed TLSMbed TLS
  • mbedtls
NoYesOct 20, 2025
CVE-2025-59438MEDIUM5.3
  • Mbed TLSMbed TLS
  • mpremote
NoYesOct 21, 2025
CVE-2025-49087LOW3.7
  • Mbed TLSMbed TLS
  • mbedtls
NoYesJul 20, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management