CVE-2021-3336
published 2021-01-29CVE-2021-3336: DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or…
PriorityP338high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.79%
52.2th percentile
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 4.6.0-3 (bookworm) | wolfssl 4.6.0-3 (bookworm) |
| wolfssl | wolfssl | < 4.7.0 | 4.7.0 |
| wolfssl | wolfssl | >= 0 < 4.6.0-3 | 4.6.0-3 |
| wolfssl | wolfssl | >= 0 < 4.6.0-3 | 4.6.0-3 |
| wolfssl | wolfssl | >= 0 < 4.6.0-3 | 4.6.0-3 |
| wolfssl | wolfssl | >= 0 < 4.6.0-3 | 4.6.0-3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qfqh-45q8-8425: DoTls13CertificateVerify in tls13
ghsa_unreviewed·2022-05-24
CVE-2021-3336 [CRITICAL] CWE-295 GHSA-qfqh-45q8-8425: DoTls13CertificateVerify in tls13
DoTls13CertificateVerify in tls13.c in wolfSSL through 4.6.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate).
OSV
CVE-2021-3336: DoTls13CertificateVerify in tls13
osv·2021-01-29·CVSS 8.1
CVE-2021-3336 [HIGH] CVE-2021-3336: DoTls13CertificateVerify in tls13
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.
Debian
CVE-2021-3336: wolfssl - DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease proce...
vendor_debian·2021·CVSS 8.1
CVE-2021-3336 [HIGH] CVE-2021-3336: wolfssl - DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease proce...
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.
Scope: local
bookworm: resolved (fixed in 4.6.0-3)
bullseye: resolved (fixed in 4.6.0-3)
forky: resolved (fixed in 4.6.0-3)
sid: resolved (fixed in 4.6.0-3)
trixie: resolved (fixed in 4.6.0-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-29
Published