CVE-2020-24585: Medium severity wolfssl wolfmqtt vulnerability
An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS applicationdata messages in epoch 0 do not produce an out-of-order error. Instead, these messages are returned to the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24585?
CVE-2020-24585 is a vulnerability that exists in the DTLS handshake implementation in wolfSSL before version 4.5.0.
What is the severity of CVE-2020-24585?
The severity of CVE-2020-24585 is medium, with a CVSS score of 5.3.
How does CVE-2020-24585 affect wolfSSL?
CVE-2020-24585 affects wolfSSL versions up to, but not including, version 4.5.0.
How can I fix CVE-2020-24585?
To fix CVE-2020-24585, you should update wolfSSL to version 4.5.0 or later.
Where can I find more information about CVE-2020-24585?
You can find more information about CVE-2020-24585 in the references provided: https://github.com/wolfSSL/wolfssl/pull/3219, https://github.com/wolfSSL/wolfssl/releases/tag/v4.5.0-stable