Tools
Why Serv-U is not affected by CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232
This article explains why Serv-U is not affected by CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232.
NVD - CVE-2025-9230 - An application trying to decrypt CMS messages encrypted using password-based encryption can trigger an out-of-bounds read and write.
NVD - CVE-2025-9231 - A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64-bit ARM platforms.
NVD - CVE-2025-9232 - An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set, and the host portion of the authority component of the HTTP URL is an IPv6 address.
Product section
Cause
CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232.
Resolution
Serv-U is not impacted by CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232 due to the following reasons:
-
CVE-2025-9230 - Serv-U code base does not use the CMS password decrypt-related API.
-
CVE-2025-9231 - Serv-U does not use SM2 algorithm.
-
CVE-2025-9232 – Serv-U does not use OpenSSL HTTP client APIs.