Denial of Service Vulnerability in Wazuh Manager Authd Service
CVE-2025-15615
6.9MEDIUM
What is CVE-2025-15615?
The Wazuh Manager's authd service is vulnerable to an improper restriction of client-initiated SSL/TLS renegotiation. This flaw allows remote attackers to send an excessive number of renegotiation requests, leading to a denial of service. By exploiting this vulnerability, attackers can overwhelm the service, consuming vital CPU resources and causing the authd service to become unavailable to legitimate users. It is crucial for users to implement mitigation strategies to avoid potential service disruptions.
Affected Version(s)
wazuh-manager <= 4.7.3 <= 4.7.3
wazuh-manager <= 4.7.3 <= 4.7.3
wazuh-manager >= 4.8.0 >= 4.8.0
