CVE-2020-25648
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker t
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability.
This flaw affects NSS versions before 3.58.
HIGH · CVSS 7.5
EPSS 0.00099
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0