CVE-2021-44718: Medium severity wolfssl wolfmqtt vulnerability
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44718?
CVE-2021-44718 is a vulnerability in wolfSSL through version 5.0.0 that allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position.
How does CVE-2021-44718 affect wolfSSL?
CVE-2021-44718 affects wolfSSL through version 5.0.0 by allowing an attacker to cause a denial of service and infinite loop in the client component.
What is the severity of CVE-2021-44718?
The severity of CVE-2021-44718 is medium with a CVSSv3 score of 5.9.
How can an attacker exploit CVE-2021-44718?
An attacker can exploit CVE-2021-44718 by sending crafted traffic from a Machine-in-the-Middle (MITM) position.
How can I fix the CVE-2021-44718 vulnerability?
To fix the CVE-2021-44718 vulnerability, update wolfSSL to version 5.0.1 or later.