天下漏洞,尽知其名
MEDIUM

CVE-2026-102759 NetX Secure TLS 空应用数据记录认证绕过漏洞

MEDIUM
暂无 CVSS 评分
原始情报

NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.

Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.