Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
2025-03-25T06:15:41.000
2025-07-17T15:57:21.527
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arm | mbed_tls | < 2.28.10 | Yes |
Application | arm | mbed_tls | < 3.6.3 | Yes |