Vulnerabilities
Vulnerable Software
Wolfssl:  >> Wolfssl  Security Vulnerabilities
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
CVSS Score
7.5
EPSS Score
0.001
Published
2019-11-21
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
CVSS Score
7.5
EPSS Score
0.002
Published
2019-11-21
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
CVSS Score
7.5
EPSS Score
0.002
Published
2019-11-21
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-11-09
wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to precisely measure the duration of signature operations, to infer information about the nonces used and potentially mount a lattice attack to recover the private key used. The issue occurs because ecc.c scalar multiplication might leak the bit length.
CVSS Score
4.7
EPSS Score
0.001
Published
2019-10-03
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignature_ex in wolfcrypt/src/asn.c.
CVSS Score
9.8
EPSS Score
0.009
Published
2019-09-24
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex.
CVSS Score
9.8
EPSS Score
0.002
Published
2019-08-26
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length, client hello length, total extensions length, PSK extension length, total identity length, and identity length contain their maximum value which is 2^16. The identity data field of the PSK extension of the packet contains the attack data, to be stored in the undefined memory (RAM) of the server. The size of the data is about 65 kB. Possibly the attacker can perform a remote code execution attack.
CVSS Score
9.8
EPSS Score
0.072
Published
2019-05-23
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
CVSS Score
9.8
EPSS Score
0.011
Published
2019-01-16
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
CVSS Score
5.9
EPSS Score
0.002
Published
2019-01-03


Contact Us

Shodan ® - All rights reserved