CVE-2025-14831

EUVD-2025-207365
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
siemens-SADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensSIMATIC CN 4100
𝑥
< V5.0
ADP
siemenssimatic_cn_4100
𝑥
< 5.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
gnutls28
bookworm
3.7.9-2+deb12u6
fixed
bookworm (security)
3.7.9-2+deb12u7
fixed
bullseye
vulnerable
bullseye (security)
3.7.1-5+deb11u9
fixed
forky
3.8.13-1
fixed
sid
3.8.13-1
fixed
trixie
3.8.9-3+deb13u3
fixed
trixie (security)
3.8.9-3+deb13u4
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gnutls
suse enterprise desktop 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise sap 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
suse enterprise server 15 SP7
3.8.3-150600.4.17.1
fixed
libgnutls-devel
suse enterprise desktop 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise sap 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
suse enterprise server 15 SP7
3.8.3-150600.4.17.1
fixed
libgnutls30
suse enterprise desktop 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise sap 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
suse enterprise server 15 SP7
3.8.3-150600.4.17.1
fixed
libgnutls30-32bit
suse enterprise desktop 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise sap 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
suse enterprise server 15 SP7
3.8.3-150600.4.17.1
fixed
libgnutls30-hmac
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
libgnutls30-hmac-32bit
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
libgnutlsxx-devel
suse enterprise desktop 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise sap 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
suse enterprise server 15 SP7
3.8.3-150600.4.17.1
fixed
libgnutlsxx28
suse enterprise server 15 SP4
3.7.3-150400.4.56.1
fixed
libgnutlsxx30
suse enterprise desktop 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise sap 15 SP7
3.8.3-150600.4.17.1
fixed
suse enterprise server 15 SP7
3.8.3-150600.4.17.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gnutls
RHEL 8
0:3.6.16-8.el8_10.5
fixed
RHEL 9
0:3.8.3-10.el9_7
fixed
gnutls-c
RHEL 8
0:3.6.16-8.el8_10.5
fixed
RHEL 9
0:3.8.3-10.el9_7
fixed
gnutls-dane
RHEL 8
0:3.6.16-8.el8_10.5
fixed
RHEL 9
0:3.8.3-10.el9_7
fixed
gnutls-devel
RHEL 8
0:3.6.16-8.el8_10.5
fixed
RHEL 9
0:3.8.3-10.el9_7
fixed
gnutls-utils
RHEL 8
0:3.6.16-8.el8_10.5
fixed
RHEL 9
0:3.8.3-10.el9_7
fixed