PoC Index

CVE-2020-24613

MEDIUM 6.8EPSS 0.9%

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

CVSS v3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
EPSS
0.86% chance of exploitation in the next 30 days, 56th percentile
Published
2020-08-24
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related