SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24613

This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

MEDIUM 6.8EPSS 0.86%

Does this matter?

Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.

Description

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.86% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
wolfssl/wolfssl
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.