Denial of Service Vulnerability in Wazuh Manager Authd Service
CVE-2025-15615

6.9MEDIUM

Key Information:

Vendor

Wazuh

Vendor
CVE Published:
27 March 2026

What is CVE-2025-15615?

The Wazuh Manager's authd service is vulnerable to an improper restriction of client-initiated SSL/TLS renegotiation. This flaw allows remote attackers to send an excessive number of renegotiation requests, leading to a denial of service. By exploiting this vulnerability, attackers can overwhelm the service, consuming vital CPU resources and causing the authd service to become unavailable to legitimate users. It is crucial for users to implement mitigation strategies to avoid potential service disruptions.

Affected Version(s)

wazuh-manager <= 4.7.3 <= 4.7.3

wazuh-manager <= 4.7.3 <= 4.7.3

wazuh-manager >= 4.8.0 >= 4.8.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Published by @vikman90.
.