The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
History

Mon, 03 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Description The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
Title Malformed KMIP response may result in access violation
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published: 2025-11-03T21:03:25.384Z

Updated: 2025-11-03T21:26:22.750Z

Reserved: 2025-11-03T20:49:39.746Z

Link: CVE-2025-12657

cve-icon Vulnrichment

Updated: 2025-11-03T21:26:17.890Z

cve-icon NVD

Status : Received

Published: 2025-11-03T21:18:50.400

Modified: 2025-11-03T21:18:50.400

Link: CVE-2025-12657

cve-icon Redhat

No data.