{"id":"CVE-2026-102759","title":"NetX Secure TLS accepts an empty application-data record without verifying its message authentication code","summary":"NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and re…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-354"],"vendor":"Eclipse Foundation","product":"NetX Duo","affected":["netx_duo >= 6.2.0 <= 6.5.1.202602"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T18:17:13.177","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102759","references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m7j3-vh25-xc8p","label":"emo@eclipse.org"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-29T17:41:02.255Z","slug":"CVE-2026-102759","body":"## Overview\n\nNetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.\n\n\n\nEmpty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}