PT-2024-6326 · Wolfssl+2 · Wolfssl+2
Armin Najafabadi
+1
·
Published
2024-06-06
·
Updated
2025-12-06
·
CVE-2024-5814
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WolfSSL (affected versions not specified)
Description
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. The issue is related to the implementation of the TLS protocol in the WolfSSL library, which is associated with access control deficiencies.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Wolfssl