CVE-2022-25640
published 2022-02-24CVE-2022-25640: In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.35%
68.4th percentile
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.2.0-1 (bookworm) | wolfssl 5.2.0-1 (bookworm) |
| wolfssl | wolfssl | < 5.2.0 | 5.2.0 |
| wolfssl | wolfssl | >= 0 < 4.6.0+p1-0+deb11u1 | 4.6.0+p1-0+deb11u1 |
| wolfssl | wolfssl | >= 0 < 5.2.0-1 | 5.2.0-1 |
| wolfssl | wolfssl | >= 0 < 5.2.0-1 | 5.2.0-1 |
| wolfssl | wolfssl | >= 0 < 5.2.0-1 | 5.2.0-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Server-side request forgery in Apache Dubbo
ghsa·2022-06-10·CVSS 6.1
CVE-2022-24969 [MEDIUM] CWE-601 Server-side request forgery in Apache Dubbo
Server-side request forgery in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
GHSA
GHSA-wx9x-cpp6-2q3w: In wolfSSL before 5
ghsa_unreviewed·2022-02-25
CVE-2022-25640 [HIGH] CWE-287 GHSA-wx9x-cpp6-2q3w: In wolfSSL before 5
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
OSV
CVE-2022-25640: In wolfSSL before 5
osv·2022-02-24·CVSS 7.5
CVE-2022-25640 [HIGH] CVE-2022-25640: In wolfSSL before 5
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
Debian
CVE-2022-25640: wolfssl - In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement ...
vendor_debian·2022·CVSS 7.5
CVE-2022-25640 [HIGH] CVE-2022-25640: wolfssl - In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement ...
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
Scope: local
bookworm: resolved (fixed in 5.2.0-1)
bullseye: resolved (fixed in 4.6.0+p1-0+deb11u1)
forky: resolved (fixed in 5.2.0-1)
sid: resolved (fixed in 5.2.0-1)
trixie: resolved (fixed in 5.2.0-1)
No detection rules found.
No public exploits indexed.
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152, CVE-2022-38153, CVE-2022-39173, and CVE-2022-42905. The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin. This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France, it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), adding mo
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152 , CVE-2022-38153 , CVE-2022-39173 , and CVE-2022-42905 . The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin . This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France , it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), add
2022-02-24
Published