CVE-2024-5814: Unverifed Ciphersuite used on a client-side TLS1.3 Downgrade

Published Aug 27, 2024
·
Updated

A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500

Affected Software

1 affected component
wolfSSL wolfssl<=5.7.0

Remediation

Information

Update wolfSSL to 5.7.2.

Event History

Aug 27, 2024
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
RemedyDescription
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-5814?

CVE-2024-5814 has been rated as a high severity vulnerability due to its potential to enable unauthorized ciphersuite negotiation.

2

How do I fix CVE-2024-5814?

To fix CVE-2024-5814, it is recommended to update to wolfSSL version 5.7.1 or later.

3

Which software is affected by CVE-2024-5814?

CVE-2024-5814 affects wolfSSL versions up to and including 5.7.0.

4

What type of attack does CVE-2024-5814 enable?

CVE-2024-5814 enables a downgrade attack where a malicious server can force a client to use an undesired ciphersuite.

5

How can I determine if my application is vulnerable to CVE-2024-5814?

To determine if your application is vulnerable to CVE-2024-5814, check if it uses wolfSSL versions up to 5.7.0 and assess its TLS1.3 downgrade capability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203