PT-2025-34839 · Unknown · Editso Fuso
Dev03301
·
Published
2025-08-27
·
Updated
2025-08-27
·
CVE-2025-9513
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
editso fuso versions up to 1.0.4-beta.7
Description:
A flaw exists due to inadequate encryption strength caused by the manipulation of the
priv key argument within the PenetrateRsaAndAesHandshake function located in the src/net/penetrate/handshake/mod.rs file. Remote exploitation is possible, but requires a high degree of complexity and is considered difficult to execute.Recommendations:
Versions prior to 1.0.4-beta.7: Address the inadequate encryption strength in the
PenetrateRsaAndAesHandshake function by carefully validating and sanitizing the priv key argument.
As a temporary workaround, consider restricting access to the PenetrateRsaAndAesHandshake function until a more permanent solution is implemented.Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Editso Fuso