PT-2024-6326 · Wolfssl+2 · Wolfssl+2

Armin Najafabadi

+1

·

Published

2024-06-06

·

Updated

2025-12-06

·

CVE-2024-5814

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WolfSSL (affected versions not specified)
Description A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. The issue is related to the implementation of the TLS protocol in the WolfSSL library, which is associated with access control deficiencies.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12644
BDU:2024-07277
CVE-2024-5814

Affected Products

Alt Linux
Debian
Wolfssl