Medium severity5.8NVD Advisory· Published Mar 27, 2026· Updated Mar 31, 2026
CVE-2025-15615
CVE-2025-15615
Description
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/wazuh/wazuh/security/advisories/GHSA-rr83-v9v7-jjhpnvdExploitVendor Advisory
- www.vulncheck.com/advisories/ssl-tls-renegotiation-dos-in-wazuh-manager-authd-servicenvdThird Party Advisory
News mentions
0No linked articles in our index yet.