CVE-2025-23419
Last modified
CVE-2025-23419 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.. EPSS estimates a 2.56% chance of exploitation in the next 30 days.
Description
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Nginx | >= 1.11.4, < 1.26.3 |
| F5 | Nginx | >= 1.27.0, < 1.27.4 |
| F5 | Nginx Plus | >= r28, < r32 |
| F5 | Nginx Plus | r32 |
| F5 | Nginx Plus | r33 |
| Debian | Debian Linux | 11.0 |
References
- https://my.f5.com/manage/s/article/K000149173Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/02/05/8Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00017.htmlIssue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-23419?
How severe is CVE-2025-23419?
How do I fix CVE-2025-23419?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-23413When users log in through the webUI or API using local authe…6.7
- CVE-2025-23414in OpenHarmony v5.0.2 and prior versions allow a local attac…7.8
- CVE-2025-23415An insufficient verification of data authenticity vulnerabil…3.1
- CVE-2025-23416Path traversal may lead to arbitrary file deletion. The scor…6.9
- CVE-2025-23417A denial of service vulnerability exists in the Modbus RTU o…7.5
- CVE-2025-23418in OpenHarmony v5.0.2 and prior versions allow a local attac…5.5
- CVE-2025-2342A vulnerability classified as critical has been found in IRO…6.9
- CVE-2025-23420in OpenHarmony v5.0.2 and prior versions allow a local attac…7.8
- CVE-2025-23421An attacker could obtain firmware files and reverse engineer…6.9
- CVE-2025-23422Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2025-23423Missing Authorization vulnerability in Smackcoders Inc., Sen…4.3
- CVE-2025-23424Cross-Site Request Forgery (CSRF) vulnerability in bnovotny …7.1
Are you affected by CVE-2025-23419?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
