cbcvebase.
CVE-2021-3336
published 2021-01-29

CVE-2021-3336: DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or…

PriorityP338high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.79%
52.2th percentile
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianwolfssl< wolfssl 4.6.0-3 (bookworm)wolfssl 4.6.0-3 (bookworm)
wolfsslwolfssl< 4.7.04.7.0
wolfsslwolfssl>= 0 < 4.6.0-34.6.0-3
wolfsslwolfssl>= 0 < 4.6.0-34.6.0-3
wolfsslwolfssl>= 0 < 4.6.0-34.6.0-3
wolfsslwolfssl>= 0 < 4.6.0-34.6.0-3

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.