CVE-2025-11935
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-21

Last updated on: 2025-12-03

Assigner: wolfSSL Inc.

Description
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when aΒ server responded to a ClientHello containing psk_dhe_ke without a key_share extension.Β The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-21
Last Modified
2025-12-03
Generated
2026-05-07
AI Q&A
2025-11-22
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
wolfssl wolfssl From 5.8.2 (inc) to 5.8.4 (exc)
apple macos *
linux linux_kernel *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-326 The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in TLS 1.3 when using pre-shared keys (PSK). A malicious or faulty server can ignore the client's request for perfect forward secrecy (PFS) by responding without the required key_share extension. As a result, the client continues the connection using PSK without PFS, which reduces the security of the connection by reusing an authenticated PSK connection that unexpectedly lacks PFS.


How can this vulnerability impact me? :

The vulnerability reduces the security of TLS 1.3 connections by allowing a server to bypass perfect forward secrecy when using pre-shared keys. This means that the confidentiality of past communications could be compromised if the PSK is later exposed, as the connection does not have the additional protection of PFS.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart