Sploitus

CVE-2022-25640

1 known exploit for CVE-2022-25640

In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.

Affected products
Alt Linux, Wolfssl
Wolfssl
< 5.2.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
1.4% (70th percentile)
Weakness
CWE-295
NVD status
Modified
Published
2022-02-24
CVE-2022-25640 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-25640

Proof-of-concept code and exploit modules indexed by Sploitus