HIGH · 7.5

CVE-2025-24970

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received v...

Vulnerability Description

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
NettyNetty>= 4.1.91, < 4.1.118
NetappActive Iq Unified Manager-
NetappOncommand Insight-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-24970?

CVE-2025-24970 is a vulnerability with a CVSS score of 7.5 (HIGH). Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received v...

How severe is CVE-2025-24970?

CVE-2025-24970 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-24970?

Check the references section above for vendor advisories and patch information. Affected products include: Netty Netty, Netapp Active Iq Unified Manager, Netapp Oncommand Insight.