VYPR
High severity8.1NVD Advisory· Published Jan 29, 2021· Updated Jun 17, 2026

CVE-2021-3336

CVE-2021-3336

Description

DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • wolfSSL/wolfSSLdescription
  • WolfSSL/Wolfssl2 versions
    cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*range: <4.7.0
    • (no CPE)range: <4.7.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.