Security Flaw in WolfSSL Prior to Version 3.2.0 Affecting Server Authentication
CVE-2014-2904
7.5HIGH
Summary
WolfSSL versions prior to 3.2.0 contain a vulnerability where the server certificate is not adequately authorized for server authentication. This flaw can lead to potential man-in-the-middle attacks, as unauthorized entities may exploit the improper validation of certificates to pose as legitimate servers. It is crucial for users of affected WolfSSL versions to update to the latest version to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved