Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
History

Fri, 27 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
Title SSL/TLS Renegotiation DoS in Wazuh Manager authd service Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service

Fri, 27 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
Title SSL/TLS Renegotiation DoS in Wazuh Manager authd service
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-03-27T16:23:03.804Z

Updated: 2026-03-27T19:43:38.523Z

Reserved: 2026-03-27T16:20:48.688Z

Link: CVE-2025-15615

cve-icon Vulnrichment

Updated: 2026-03-27T17:39:45.592Z

cve-icon NVD

Status : Received

Published: 2026-03-27T17:16:26.767

Modified: 2026-03-27T17:16:26.767

Link: CVE-2025-15615

cve-icon Redhat

No data.