Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-2800Improper Certificate Validation in Wolfssl

Severity
9.8CRITICALNVD
EPSS
8.9%
top 7.43%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 24
Latest updateMay 13

Description

A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the attacker needs to supply a malicious x509 certificate to either a server or a client application using this library.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/wolfssl< wolfssl 3.12.0+dfsg-1 (bookworm)
Debianwolfssl/wolfssl< 3.12.0+dfsg-1+3
NVDwolfssl/wolfssl3.10.2
CVEListV5wolfssl/wolfssl3.10.2

🔴Vulnerability Details

2
GHSA
GHSA-59h3-rq7p-jqmv: A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 32022-05-13
OSV
CVE-2017-2800: A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 32017-05-24

💥Exploits & PoCs

2
Exploit-DB
Cisco IOS - Remote Code Execution2018-01-05
Exploit-DB
wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One2017-05-09

📋Vendor Advisories

9
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points MAC Authentication Bypass Vulnerability2017-11-01
Cisco
Cisco Aironet 1560, 2800, and 3800 Series Access Point Platforms 802.11 Denial of Service Vulnerability2017-11-01
Cisco
Cisco Aironet 1560, 2800, and 3800 Series Access Point Platforms Extensible Authentication Protocol Denial of Service Vulnerability2017-11-01
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points Plug-and-Play Arbitrary Code Execution Vulnerability2017-05-03
Debian
CVE-2017-2800: wolfssl - A specially crafted x509 certificate can cause a single out of bounds byte overw...2017

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: WolfSSL library X.509 Certificate Text Parsing Code Execution Vulnerability2017-05-08
Talos
Vulnerability Spotlight: WolfSSL library X.509 Certificate Text Parsing Code Execution Vulnerability2017-05-08
CVE-2017-2800 — Improper Certificate Validation | cvebase