Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary amount of simultaneously incoming connections (TCP, UDP and Unix socket) for the services letmeind and letmeinfwd. Therefore, the command line option num-connections is not effective and does not limit the number of simultaneously incoming connections. This issue has been patched in version 10.2.1.
History

Tue, 24 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Jun 2025 03:45:00 +0000

Type Values Removed Values Added
Description Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary amount of simultaneously incoming connections (TCP, UDP and Unix socket) for the services letmeind and letmeinfwd. Therefore, the command line option num-connections is not effective and does not limit the number of simultaneously incoming connections. This issue has been patched in version 10.2.1.
Title Letmein connection limiter allows an arbitrary amount of simultaneous connections
Weaknesses CWE-770
CWE-799
References
Metrics cvssV4_0

{'score': 1.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-24T03:13:29.370Z

Updated: 2025-06-24T14:42:51.785Z

Reserved: 2025-06-18T03:55:52.036Z

Link: CVE-2025-52570

cve-icon Vulnrichment

Updated: 2025-06-24T14:42:32.108Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-24T04:15:50.360

Modified: 2025-06-26T18:58:14.280

Link: CVE-2025-52570

cve-icon Redhat

No data.