7.5
CVSSv3

CVE-2020-25648

Published: 20/10/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote malicious user to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions prior to 3.58.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla network security services

redhat enterprise linux 7.0

redhat enterprise linux 8.0

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

oracle communications offline mediation controller 12.0.0.3.0

oracle communications pricing design center 12.0.0.3.0

oracle jd edwards enterpriseone tools

Vendor Advisories

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 13 This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library The highest threat from this vulnerability is to system availability (CVE-2020-25648) ...
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 13 This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library The highest threat from this vulnerability is to system availability (CVE-2020-25648) ...

Github Repositories

A collection of SSL/TLS security related resources.

Awesome SSL/TLS Hacks Contents Awesome SSL/TLS Hacks Contents SSL/TLS Protocol History SSL/TLS Hacks Cryptographic Issues CBC Issues RC4 Issues Compression Issues RSA Issues Implementation Issues Some Open Source Implementations of SSL/TLS OpenSSL Version History Vulnerabilities Fizz Vulnerabilities OpenSSL Vulnerabilities Tools Fuzzing Programing Scanning Others

A collection of SSL/TLS security related resources.

Awesome SSL/TLS Hacks Contents Awesome SSL/TLS Hacks Contents SSL/TLS Protocol History SSL/TLS Hacks Cryptographic Issues CBC Issues RC4 Issues Compression Issues RSA Issues Implementation Issues Some Open Source Implementations of SSL/TLS OpenSSL Version History Vulnerabilities Fizz Vulnerabilities OpenSSL Vulnerabilities Tools Fuzzing Programing Scanning Others