PT-2020-15751 · Wolfssl · Wolfssl

Paul Fiterau

+1

·

Published

2020-08-21

·

Updated

2020-08-26

·

CVE-2020-24585

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 4.5.0
Description An issue was discovered in the DTLS handshake implementation. Clear DTLS application data messages in epoch 0 do not produce an out-of-order error, instead, these messages are returned to the application.
Recommendations For versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-24585

Affected Products

Wolfssl