Vulnerabilidades em wolfSSL

94 resultados
Análise Vexday

O histórico de vulnerabilidades do wolfSSL acumula 91 CVEs catalogadas, com uma concentração expressiva de 55 entradas surgidas nos últimos 90 dias, o que indica um período recente de escrutínio intensificado ou atualização de catalogação. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma CVE confirmada em uso por agentes de ameaça no momento, embora a CVE-2017-13099 — associada à falha de tipo mais recorrente na biblioteca, CWE-295 (validação inadequada de certificados) — apresente o maior score EPSS observado (0,2492), sugerindo probabilidade não desprezível de exploração futura. As 7 CVEs de severidade crítica e a existência de prova de conceito pública para ao menos uma vulnerabilidade reforçam a necessidade de atenção contínua ao processo de atualização em ambientes que dependem dessa biblioteca TLS/SSL embarcada. Equipes de segurança devem priorizar a revisão de versões em uso, especialmente em contextos de IoT e sistemas embarcados onde ciclos de patching tendem a ser mais lentos.

CVE-2017-13099HIGHwolfSSL Bleichenbacher/ROBOTEPSS 24.9%CVE-2017-2800HIGHA specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifEPSS 8.5%CVE-2024-0901HIGHSEGV and out of bounds memory read from malicious packetEPSS 0.7%CVE-2023-3724CRITICALTLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionEPSS 0.7%CVE-2023-6936MEDIUM Heap-buffer over-read with WOLFSSL_CALLBACKSEPSS 0.6%CVE-2024-1545MEDIUMFault Injection of RSA encryption in WolfCryptEPSS 0.6%CVE-2026-6679HIGHDTLS 1.3 ACK serialization heap buffer overflow via integer truncationEPSS 0.6%CVE-2024-5991CRITICALBuffer overread in domain name matchingEPSS 0.6%CVE-2023-6935MEDIUMMarvin Attack vulnerability in SP Math All RSAEPSS 0.5%CVE-2023-6937MEDIUMImproper (D)TLS key boundary enforcementEPSS 0.5%CVE-2026-3548HIGHBuffer overflow in CRL number parsing in wolfSSLEPSS 0.5%CVE-2024-5814MEDIUMUnverifed Ciphersuite used on a client-side TLS1.3 DowngradeEPSS 0.5%CVE-2024-2881MEDIUMFault Injection of EdDSA signature in WolfCryptEPSS 0.5%CVE-2026-5194CRITICALwolfSSL ECDSA Certificate VerificationEPSS 0.4%CVE-2026-5264HIGHDTLS 1.3 ACK heap buffer overflowEPSS 0.4%CVE-2025-11936MEDIUMPotential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHelloEPSS 0.4%CVE-2026-5477HIGHPrefix-substitution forgery via integer overflow in wolfCrypt CMACEPSS 0.4%CVE-2026-55958HIGHRenesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessageEPSS 0.4%CVE-2025-11625CRITICALHost verification bypass and credential leakEPSS 0.4%CVE-2026-5503MEDIUMout-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicNameEPSS 0.4%