{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T18:46:03.639","vulnerabilities":[{"cve":{"id":"CVE-2025-13476","sourceIdentifier":"cret@cert.org","published":"2026-03-05T19:15:58.283","lastModified":"2026-06-17T08:34:12.950","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)"},{"lang":"es","value":"El modo Cloak de Rakuten Viber en Android v25.7.2.0g y Windows v25.6.0.0–v25.8.1.0 utiliza una huella digital TLS ClientHello estática y predecible que carece de diversidad de extensiones, lo que permite a los sistemas de Inspección Profunda de Paquetes (DPI) identificar y bloquear trivialmente el tráfico de proxy, socavando la elusión de la censura. (CWE-327)"}],"affected":[{"source":"cret@cert.org","affectedData":[{"vendor":"Rakuten Viber","product":"Rakuten Viber Cloak - Android","versions":[{"version":"25.7.2.0g","lessThan":"27.2.0.0g","versionType":"custom","status":"affected"}]},{"vendor":"Rakuten Viber","product":"Rakuten Viber Cloak - Windows","versions":[{"version":"v25.6.0.0","lessThan":"v27.3.0.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-06T10:34:45.858741Z","id":"CVE-2025-13476","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-327"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rakuten:viber:*:*:*:*:*:windows:*:*","versionStartIncluding":"25.6.0","versionEndIncluding":"25.8.1.0","matchCriteriaId":"F75AF4DA-3BBA-44F1-80FA-6FF49AB18C20"},{"vulnerable":true,"criteria":"cpe:2.3:a:rakuten:viber:9.3.0.6:25.7.2.0g:*:*:*:android:*:*","matchCriteriaId":"758AEEB0-8E18-48D2-A8A5-662BAAE54CFF"}]}]}],"references":[{"url":"https://www.viber.com/en/download/","source":"cret@cert.org","tags":["Product"]},{"url":"https://www.kb.cert.org/vuls/id/772695","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}