CVE-2017-8855: High severity wolfssl wolfmqtt vulnerability
Published May 9, 2017
·Updated
wolfSSL before 3.11.0 does not prevent wcDhAgree from accepting a malformed DH key.
Affected Software
1 affected component
wolfSSL wolfssl<=3.10.4
Remediation
Event History
May 9, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8855?
CVE-2017-8855 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-8855?
To fix CVE-2017-8855, upgrade wolfSSL to version 3.11.0 or later.
3
What software is affected by CVE-2017-8855?
CVE-2017-8855 affects wolfSSL versions prior to 3.11.0.
4
What type of vulnerability is CVE-2017-8855?
CVE-2017-8855 is a cryptographic vulnerability related to accepting malformed DH keys.
5
Can CVE-2017-8855 lead to security issues?
Yes, CVE-2017-8855 can potentially allow attackers to exploit the vulnerability and create security risks.