CVE Database
/

CVE-2024-5814

Back to search

CVE-2024-5814

Published: Aug 27, 2024

Modified: Aug 27, 2024

PUBLISHED

Description

A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500

VendorProductVersions

wolfSSL

wolfSSL

affected
0 - <= 5.7.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now