Improper Connection Limitation in Letmein Port Knocker
CVE-2025-52570
1.7LOW
What is CVE-2025-52570?
The Letmein port knocker, prior to version 10.2.1, suffers from an improper implementation of the connection limiter. This flaw permits an unlimited number of simultaneous incoming connections for the services letmeind and letmeinfwd, thus compromising the effectiveness of the num-connections command line option. The vulnerability allows attackers to exploit this oversight, potentially leading to service disruptions and resource exhaustion. A patch has been released to rectify this issue in version 10.2.1.
Affected Version(s)
letmein < 10.2.1