PT-2023-25848 · Wolfssl · Wolfssl
Johannes
·
Published
2023-07-17
·
Updated
2023-07-28
·
CVE-2023-3724
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
When a TLS 1.3 client connects to a malicious server without receiving a PSK (pre shared key) extension or a KSE (key share extension), it uses a default predictable buffer for the IKM (Input Keying Material) value. This compromises the generated session master secret key, allowing an eavesdropper to reconstruct it and potentially access or meddle with message contents. The issue does not affect client validation of connected servers or expose private key information but could result in an insecure TLS 1.3 session.
Recommendations
Update the version of wolfSSL used to resolve the issue. As a temporary workaround, consider restricting connections to trusted servers to minimize the risk of exploitation.
Fix
RCE
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wolfssl