CVE-2014-2904: High severity wolfSSL wolfssl vulnerability
Published Nov 21, 2019
·Updated
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
Affected Software
2 affected componentsFixes available
wolfSSL wolfssl<3.2.0
debian/wolfssl
4.6.0+p1-0+deb11u25.5.4-2+deb12u25.7.2-0.1+deb13u15.8.4-1
Remediation
Patch Available
Event History
Nov 21, 2019
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
Description
Feb 18, 2026
Data Sourced
via Debian·06:57 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2014-2904?
CVE-2014-2904 is a vulnerability in wolfssl before version 3.2.0 where the server certificate is not properly authorized for server authentication.
2
How severe is CVE-2014-2904?
CVE-2014-2904 has a severity rating of 7.5 (high).
3
How does CVE-2014-2904 affect wolfssl?
CVE-2014-2904 affects wolfssl versions up to, but excluding, version 3.2.0.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2014-2904?
CVE-2014-2904 is associated with CWE-287: Improper Authentication.
5
Are there any references available for CVE-2014-2904?
Yes, you can refer to the following links: [1](http://www.openwall.com/lists/oss-security/2014/04/18/2), [2](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792646), [3](https://security-tracker.debian.org/tracker/CVE-2014-2904).