Critical severity9.1NVD Advisory· Published Jan 18, 2022· Updated Jun 17, 2026
CVE-2022-23408
CVE-2022-23408
Description
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in BuildMessage in internal.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/wolfSSL/wolfssl/blob/master/ChangeLog.mdnvdRelease NotesThird Party Advisory
- github.com/wolfSSL/wolfssl/pull/4710nvdThird Party Advisory
News mentions
0No linked articles in our index yet.