CVE-2020-25648: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.

Affected products

  • Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
  • Mozilla Network Security Services: before 3.58 (fixed in 3.58)
  • Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
  • Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
  • Oracle Jd Edwards Enterpriseone Tools: before 9.2.6.0 (fixed in 9.2.6.0)
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only

Published 2020-10-20. Last modified 2026-06-17.