CVE & CISA-KEV Catalog

CVE-2025-0343

HIGH
7.5
CVSS v3
NVD

Description

Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions. This crash is caused by a confusion in the ASN.1 library itself which assumes that certain objects can only be provided in either constructed or primitive forms, and will trigger a preconditionFailure if that constraint isn't met. Importantly, these constraints are actually required to be true in DER, but that correctness wasn't enforced on the early node parser side so it was incorrect to rely on it later on in decoding, which is what the library did. These crashes can be triggered when parsing any DER/BER format object. There is no memory-safety issue here: the crash is a graceful one from the Swift runtime. The impact of this is that it can be used as a denial-of-service vector when parsing BER/DER data from unknown sources, e.g. when parsing TLS certificates.

How to fix

No published remediation has been found for this vulnerability's affected products yet.

Mitigation guidance may be in the linked vendor advisories in the References section below.

TridentStack Control tracks known vulnerabilities across your Windows, macOS, and Linux fleet and shows the fix as soon as one is published. See how it works

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit Intelligence

0.33%probability of exploitation in 30 days
25thpercentile

Low risk: more likely to be exploited than 25% of all known CVEs.

References

Other references1

Related Vulnerabilities

Other CWE-228 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2018-5381Medium6.531%-Fix
CVE-2021-38443Medium6.62.2%-Fix
CVE-2020-27847Critical9.81.7%-Fix
CVE-2021-36199Medium5.31.0%--
CVE-2026-42100High7.50.7%--
CVE-2024-21612High7.50.5%-Fix
Embed a live status badge for CVE-2025-0343
CVE-2025-0343 severity badge

Markdown

[![CVE-2025-0343](https://tridentstack.com/cve/badge/CVE-2025-0343.svg)](https://tridentstack.com/cve/CVE-2025-0343)

HTML

<a href="https://tridentstack.com/cve/CVE-2025-0343"><img src="https://tridentstack.com/cve/badge/CVE-2025-0343.svg" alt="CVE-2025-0343"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-03-24.