PT-2025-30101 · Wolfssl+1 · Wolfssl+1

Thomas Leong

·

Publicado

2025-07-18

·

Atualizado

2026-01-06

·

CVE-2025-7395

CVSS v4.0

9.2

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:X/U:Red
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description A certificate verification error occurs in wolfSSL when built with the WOLFSSL SYS CA CERTS and WOLFSSL APPLE NATIVE CERT VALIDATION options. This results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted Certificate Authority (CA) to be accepted, regardless of the hostname.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-7395

Produtos afetados

Debian
Wolfssl