VYPR

Vendor CVEs

WolfSSL

All CVEs

163 total · sorted by risk
  • CVE-2021-37155CriJul 21, 2021
    risk 0.00cvss 9.8epss 0.01

    wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number in the OCSP response.

  • CVE-2021-3336HigJan 29, 2021
    risk 0.00cvss 8.1epss 0.01

    DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can…

  • CVE-2020-12457HigAug 21, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way involving more than one in a row, the server becomes stuck in the ProcessReply()…

  • CVE-2020-11735MedJun 25, 2020
    risk 0.00cvss 5.3epss 0.01

    The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."

  • CVE-2020-11713HigApr 12, 2020
    risk 0.00cvss 7.5epss 0.02

    wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.

  • CVE-2019-19963MedDec 25, 2019
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

  • CVE-2019-19962HigDec 25, 2019
    risk 0.00cvss 7.5epss 0.01

    wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

  • CVE-2019-19960MedDec 25, 2019
    risk 0.00cvss 5.3epss 0.01

    In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.

  • CVE-2018-16870MedJan 3, 2019
    risk 0.00cvss 5.9epss 0.02

    It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.

  • CVE-2018-12436MedJun 15, 2018
    risk 0.00cvss 4.7epss 0.00

    wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine…

  • CVE-2014-2900Apr 22, 2014
    risk 0.00cvss epss 0.01

    wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.

  • CVE-2014-2899Apr 22, 2014
    risk 0.00cvss epss 0.02

    wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.

  • CVE-2013-1623Feb 8, 2013
    risk 0.00cvss epss 0.02

    The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and…

Page 4 of 4