Vulnerability Details CVE-2025-24970
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-24970
-
cpe:2.3:a:netapp:active_iq_unified_manager:-
-
cpe:2.3:a:netapp:oncommand_insight:-
-
cpe:2.3:a:netty:netty:4.1.100
-
cpe:2.3:a:netty:netty:4.1.101
-
cpe:2.3:a:netty:netty:4.1.102
-
cpe:2.3:a:netty:netty:4.1.103
-
cpe:2.3:a:netty:netty:4.1.104
-
cpe:2.3:a:netty:netty:4.1.105
-
cpe:2.3:a:netty:netty:4.1.106
-
cpe:2.3:a:netty:netty:4.1.107
-
cpe:2.3:a:netty:netty:4.1.108
-
cpe:2.3:a:netty:netty:4.1.109
-
cpe:2.3:a:netty:netty:4.1.110
-
cpe:2.3:a:netty:netty:4.1.111
-
cpe:2.3:a:netty:netty:4.1.112
-
cpe:2.3:a:netty:netty:4.1.113
-
cpe:2.3:a:netty:netty:4.1.114
-
cpe:2.3:a:netty:netty:4.1.115
-
cpe:2.3:a:netty:netty:4.1.116
-
cpe:2.3:a:netty:netty:4.1.117
-
cpe:2.3:a:netty:netty:4.1.91
-
cpe:2.3:a:netty:netty:4.1.92
-
cpe:2.3:a:netty:netty:4.1.93
-
cpe:2.3:a:netty:netty:4.1.94
-
cpe:2.3:a:netty:netty:4.1.95
-
cpe:2.3:a:netty:netty:4.1.96
-
cpe:2.3:a:netty:netty:4.1.97
-
cpe:2.3:a:netty:netty:4.1.98
-
cpe:2.3:a:netty:netty:4.1.99