CVE-2015-6925: High severity wolfssl wolfmqtt vulnerability
Published Jan 22, 2016
·Updated
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.
Affected Software
1 affected component
wolfSSL wolfssl<=3.6.6
Event History
Jan 22, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6925?
CVE-2015-6925 is classified as a denial of service vulnerability, allowing attackers to exhaust resources.
2
How do I fix CVE-2015-6925?
To mitigate CVE-2015-6925, upgrade wolfSSL to version 3.6.8 or later.
3
What causes the vulnerability in CVE-2015-6925?
CVE-2015-6925 is caused by insufficient validation of crafted DTLS cookies in a ClientHello message.
4
Who is affected by CVE-2015-6925?
Any user or system utilizing wolfSSL versions prior to 3.6.8 is susceptible to CVE-2015-6925.
5
Can CVE-2015-6925 lead to data breaches?
CVE-2015-6925 does not directly lead to data breaches, but it can disrupt service availability.