Improper Connection Limitation in Letmein Port Knocker
CVE-2025-52570

1.7LOW

Key Information:

Vendor

Mbuesch

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-52570?

The Letmein port knocker, prior to version 10.2.1, suffers from an improper implementation of the connection limiter. This flaw permits an unlimited number of simultaneous incoming connections for the services letmeind and letmeinfwd, thus compromising the effectiveness of the num-connections command line option. The vulnerability allows attackers to exploit this oversight, potentially leading to service disruptions and resource exhaustion. A patch has been released to rectify this issue in version 10.2.1.

Affected Version(s)

letmein < 10.2.1

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52570 : Improper Connection Limitation in Letmein Port Knocker