PT-2026-102771 · Unknown · Netx Secure Tls

CVE-2026-102759

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NetX Secure TLS (affected versions not specified)
Description NetX Secure TLS accepts empty application-data records without verifying the message authentication code (MAC). Within the nx secure verify mac() function, a decrypted application record with a length equal to the negotiated MAC size is incorrectly treated as valid. This results in the function returning success and advancing the receive sequence number without generating or comparing the received MAC. Empty TLS application-data records are legal and are often used by TLS 1.0 implementations as a mitigation for BEAST (Browser Exploit Against SSL/TLS), a cryptographic attack that targets the Cipher Block Chaining (CBC) mode in TLS 1.0.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102759
GHSA-M7J3-VH25-XC8P

Affected Products

Netx Secure Tls