CVE-2025-41361
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-06
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an uncontrolled resource consumption issue in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04 devices. It occurs because the devices improperly handle TLS requests sent to PROCOME sockets. When TLS requests are sent to these PROCOME ports, the device may reboot unexpectedly, causing a denial of service. Exploiting this requires that PROCOME ports are configured, active, and have communications encryption enabled.
How can this vulnerability impact me? :
This vulnerability can cause affected devices to reboot unexpectedly when they receive certain TLS requests on PROCOME ports, leading to a denial of service. This means the device becomes unavailable or unresponsive, potentially disrupting services or operations relying on these devices.