Unrated severityNVD Advisory· Published Feb 24, 2022· Updated Aug 3, 2024
CVE-2022-25640
CVE-2022-25640
Description
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- github.com/wolfSSL/wolfssl/pull/4831mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.