PT-2025-24096 · Zlf+1 · Zlf+1
Published
2025-06-05
·
Updated
2025-06-06
·
CVE-2025-41361
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
IDF versions 0.10.0-0C03-03
ZLF versions 0.10.0-0C03-04
Description
The devices improperly handle TLS requests associated with PROCOME sockets. This can cause the device to reboot, resulting in a denial of service when TLS requests are sent to those PROCOME ports. To exploit this issue, PROCOME ports must be configured and active, with communications encryption active.
Recommendations
For IDF version 0.10.0-0C03-03, consider disabling the PROCOME ports until a patch is available to prevent unauthorized reboot via TLS requests.
For ZLF version 0.10.0-0C03-04, restrict access to the PROCOME ports to minimize the risk of exploitation.
As a temporary workaround, consider disabling communications encryption for PROCOME ports until the issue is resolved.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Idf
Zlf