CVE-2026-102759
Awaiting Analysis Awaiting Analysis - Queue

NetX Secure TLS Empty Application-Data Record MAC Bypass

Vulnerability report for CVE-2026-102759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared. Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves NetX Secure TLS incorrectly accepting empty application-data records without verifying their message authentication code. The function _nx_secure_verify_mac treats a decrypted application record with length equal to the MAC size as valid, skipping the actual MAC comparison. This allows invalid records to be processed as legitimate.

Impact Analysis

This flaw could allow attackers to bypass security checks by sending empty TLS application-data records. It may lead to unauthorized data access or manipulation if exploited, though the impact depends on the specific TLS implementation and environment.

Mitigation Strategies

Update NetX Secure TLS to the latest patched version to address the empty application-data record validation issue. Review TLS 1.0 implementations for BEAST mitigation compatibility and ensure proper MAC verification is enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart