PT-2025-24096 · Zlf+1 · Zlf+1

Published

2025-06-05

·

Updated

2025-06-06

·

CVE-2025-41361

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions IDF versions 0.10.0-0C03-03 ZLF versions 0.10.0-0C03-04
Description The devices improperly handle TLS requests associated with PROCOME sockets. This can cause the device to reboot, resulting in a denial of service when TLS requests are sent to those PROCOME ports. To exploit this issue, PROCOME ports must be configured and active, with communications encryption active.
Recommendations For IDF version 0.10.0-0C03-03, consider disabling the PROCOME ports until a patch is available to prevent unauthorized reboot via TLS requests. For ZLF version 0.10.0-0C03-04, restrict access to the PROCOME ports to minimize the risk of exploitation. As a temporary workaround, consider disabling communications encryption for PROCOME ports until the issue is resolved.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2026-00063
CVE-2025-41361

Affected Products

Idf
Zlf