Vulnerabilities > Wolfssl

DATE CVE VULNERABILITY TITLE RISK
2023-07-17 CVE-2023-3724 Improper Certificate Validation vulnerability in Wolfssl
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret.
network
low complexity
wolfssl CWE-295
8.8
2022-11-07 CVE-2022-42905 Out-of-bounds Read vulnerability in Wolfssl
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes.
network
low complexity
wolfssl CWE-125
critical
9.1
2022-10-15 CVE-2022-42961 Unspecified vulnerability in Wolfssl
An issue was discovered in wolfSSL before 5.5.0.
network
low complexity
wolfssl
5.3
2022-09-29 CVE-2022-39173 Out-of-bounds Write vulnerability in Wolfssl
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake.
network
low complexity
wolfssl CWE-787
7.5
2022-08-31 CVE-2022-38153 Allocation of Resources Without Limits or Throttling vulnerability in Wolfssl 5.3.0
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable.
network
high complexity
wolfssl CWE-770
5.9
2022-08-31 CVE-2022-38152 Improper Check for Unusual or Exceptional Conditions vulnerability in Wolfssl
An issue was discovered in wolfSSL before 5.5.0.
network
low complexity
wolfssl CWE-754
7.5
2022-02-24 CVE-2022-25638 Improper Certificate Validation vulnerability in Wolfssl
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server.
network
wolfssl CWE-295
4.3
2022-02-24 CVE-2022-25640 Improper Certificate Validation vulnerability in Wolfssl
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication.
network
low complexity
wolfssl CWE-295
7.5
2022-01-18 CVE-2022-23408 Use of Insufficiently Random Values vulnerability in Wolfssl
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.
network
low complexity
wolfssl CWE-330
6.4
2022-01-01 CVE-2021-45932 Out-of-bounds Write vulnerability in Wolfssl Wolfmqtt 1.9
wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacket).
network
wolfssl CWE-787
4.3