PT-2026-3230 · Tls 1.3+1 · Tls 1.3+1
Coia Prant
·
Published
2025-01-01
·
Updated
2026-05-21
·
CVE-2025-61730
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
versions prior to TLS 1.3
Description
A flaw exists in the TLS 1.3 handshake process where messages spanning encryption level boundaries can be processed prematurely. This can lead to minor information disclosure if a network-local attacker injects messages during the handshake. Specifically, if multiple messages are sent in records that cross encryption level boundaries, such as the Client Hello and Encrypted Extensions messages, subsequent messages might be processed before the encryption level is fully established.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Tls 1.3