PT-2026-102771 · Unknown · Netx Secure Tls
CVE-2026-102759
·
Published
2026-09-29
·
Updated
2026-09-29
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NetX Secure TLS (affected versions not specified)
Description
NetX Secure TLS accepts empty application-data records without verifying the message authentication code (MAC). Within the
nx secure verify mac() function, a decrypted application record with a length equal to the negotiated MAC size is incorrectly treated as valid. This results in the function returning success and advancing the receive sequence number without generating or comparing the received MAC. Empty TLS application-data records are legal and are often used by TLS 1.0 implementations as a mitigation for BEAST (Browser Exploit Against SSL/TLS), a cryptographic attack that targets the Cipher Block Chaining (CBC) mode in TLS 1.0.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netx Secure Tls