Information Leak in OpenWrt's ustream-ssl Library
CVE-2019-5101
4MEDIUM
What is CVE-2019-5101?
An information leak vulnerability exists in the ustream-ssl library of OpenWrt, where improper handling of invalid SSL certificates may allow attackers to conduct man-in-the-middle attacks. When a connection to a remote server is established, the server's SSL certificate undergoes verification; however, if the certificate is found to be invalid, no preventive measures are enforced. This behavior enables an attacker to present any certificate, resulting in the potential interception of sensitive data exchanged between the client and the server during the initial connection phase.
Affected Version(s)
OpenWRT OpenWrt 15.05.1, via wget (busybox)
OpenWRT OpenWrt 18.06.4, via wget (uclient-fetch)
