cbcvebase.
CVE-2023-3724
published 2023-07-17

CVE-2023-3724: If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable…

PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.65%
47.2th percentile
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a potentially known IKM value when generating the session master secret key compromises the key generated, allowing an eavesdropper to reconstruct it and potentially allowing access to or meddling with message contents in the session. This issue does not affect client validation of connected servers, nor expose private key information, but could result in an insecure TLS 1.3 session when not controlling both sides of the connection. wolfSSL recommends that TLS 1.3 client side users update the version of wolfSSL used.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianwolfssl< wolfssl 5.5.4-2+deb12u1 (bookworm)wolfssl 5.5.4-2+deb12u1 (bookworm)
msrccbl2_libtiff_4.4.0-8_on_cbl_mariner_2.0
msrccbl2_mariadb_10.6.9-3.cm2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_libtiff_4.5.0-1_on_cbl_mariner_1.0
wolfsslwolfssl< 5.6.25.6.2
wolfsslwolfssl>= 0 < 4.6.0+p1-0+deb11u24.6.0+p1-0+deb11u2
wolfsslwolfssl>= 0 < 5.5.4-2+deb12u15.5.4-2+deb12u1
wolfsslwolfssl>= 0 < 5.5.4-2.15.5.4-2.1
wolfsslwolfssl>= 0 < 5.5.4-2.15.5.4-2.1
wolfsslwolfssl3.14.0 – 5.6.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian9.1CRITICAL
vendor_msrc8.8HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.