CVE-2021-38597
published 2021-08-12CVE-2021-38597: wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.48%
38.5th percentile
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.0.0-1 (bookworm) | wolfssl 5.0.0-1 (bookworm) |
| wolfssl | wolfssl | < 4.8.1 | 4.8.1 |
| wolfssl | wolfssl | >= 0 < 4.6.0+p1-0+deb11u1 | 4.6.0+p1-0+deb11u1 |
| wolfssl | wolfssl | >= 0 < 5.0.0-1 | 5.0.0-1 |
| wolfssl | wolfssl | >= 0 < 5.0.0-1 | 5.0.0-1 |
| wolfssl | wolfssl | >= 0 < 5.0.0-1 | 5.0.0-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-38597: wolfssl - wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations o...
vendor_debian·2021·CVSS 5.9
CVE-2021-38597 [MEDIUM] CVE-2021-38597: wolfssl - wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations o...
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
bullseye: resolved (fixed in 4.6.0+p1-0+deb11u1)
forky: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
GHSA
GHSA-r434-53mc-rhw4: wolfSSL before 4
ghsa_unreviewed·2022-05-24
CVE-2021-38597 [MEDIUM] CWE-345 GHSA-r434-53mc-rhw4: wolfSSL before 4
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
OSV
CVE-2021-38597: wolfSSL before 4
osv·2021-08-12·CVSS 5.9
CVE-2021-38597 [MEDIUM] CVE-2021-38597: wolfSSL before 4
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-12
Published