CVE-2014-2897: Critical severity wolfssl wolfmqtt vulnerability
Published Jan 28, 2020
·Updated
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMAC, which triggers an out-of-bounds read.
Affected Software
1 affected component
wolfSSL wolfssl>=2.5.0<2.9.4
Event History
Jan 28, 2020
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this SSL issue in wolfSSL CyaSSL?
The vulnerability ID is CVE-2014-2897.
2
What is the severity of CVE-2014-2897?
The severity of CVE-2014-2897 is critical with a severity value of 9.8.
3
What is the affected software for CVE-2014-2897?
The affected software for CVE-2014-2897 is wolfSSL CyaSSL version 2.5.0 before 2.9.4.
4
What is the impact of CVE-2014-2897?
The impact of CVE-2014-2897 is unspecified but can have an out-of-bounds read if exploited.
5
How can I fix the vulnerability in CVE-2014-2897?
To fix the vulnerability in CVE-2014-2897, update wolfSSL CyaSSL to version 2.9.4 or later.