Vulnerability Description
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing validation of PSK length provided in the user message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Threadx Netx Duo | <= 6.4.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-55082?
CVE-2025-55082 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing validation of PSK le...
How severe is CVE-2025-55082?
CVE-2025-55082 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55082?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Threadx Netx Duo.