First published: Fri Sep 02 2022(Updated: )
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WolfSSL wolfssl | <=5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44718 is a vulnerability in wolfSSL through version 5.0.0 that allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position.
CVE-2021-44718 affects wolfSSL through version 5.0.0 by allowing an attacker to cause a denial of service and infinite loop in the client component.
The severity of CVE-2021-44718 is medium with a CVSSv3 score of 5.9.
An attacker can exploit CVE-2021-44718 by sending crafted traffic from a Machine-in-the-Middle (MITM) position.
To fix the CVE-2021-44718 vulnerability, update wolfSSL to version 5.0.1 or later.