Lucene search

K
osvGoogleOSV:CVE-2020-25648
HistoryOct 20, 2020 - 10:15 p.m.

CVE-2020-25648

2020-10-2022:15:43
Google
osv.dev
6

6.5 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.5%

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

References