PT-2024-19495 · Kwik · Kwik
Quictester
·
Published
2024-05-28
·
Updated
2024-08-22
·
CVE-2024-22590
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kwik version 745fd4e2
Description
The TLS engine does not track the current state of the connection, allowing Client Hello messages to be overwritten at any time, including after a connection has been established.
Recommendations
For version 745fd4e2, consider disabling the TLS engine until a patch is available to prevent Client Hello messages from being overwritten. Restrict access to the TLS engine to minimize the risk of exploitation. Avoid using the TLS engine for establishing connections until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kwik