VulnerabilityModified
CVE-2021-3336
The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.
HIGH 8.1EPSS 0.79%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- wolfssl/wolfssl
- Source
- cve@mitre.org
References
- https://github.com/wolfSSL/wolfssl/pull/3676Patch, Third Party Advisory
- https://www.wolfssl.com/docs/security-vulnerabilitiesVendor Advisory
- https://github.com/wolfSSL/wolfssl/pull/3676Patch, Third Party Advisory
- https://www.wolfssl.com/docs/security-vulnerabilitiesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.