AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-25648

HIGH · CVSS 7.5 EPSS 3.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-10-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2020-25648
Severity
HIGH
CVSS
7.5
EPSS
3.90%

Original NVD Description

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

Related CVEs

Other vulnerabilities affecting the same vendor(s)