Certificate Validation Vulnerability in wolfSSL TLS 1.3 Client Authentication
CVE-2022-25638

6.5MEDIUM

Key Information:

Vendor
Wolfssl
Status
Vendor
CVE Published:
24 February 2022

Summary

A certificate validation bypass vulnerability exists in wolfSSL versions prior to 5.2.0, allowing a TLS 1.3 client to potentially evade authentication checks when connecting to a TLS 1.3 server. This issue arises when there is a discrepancy in the sig_algo field between the certificate_verify message and the certificate message, posing a security risk to systems utilizing affected wolfSSL versions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.