CVE-2020-25648: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
Affected products
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- Mozilla Network Security Services: before 3.58 (fixed in 3.58)
- Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
- Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
- Oracle Jd Edwards Enterpriseone Tools: before 9.2.6.0 (fixed in 9.2.6.0)
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
Published 2020-10-20. Last modified 2026-06-17.