Back to search
CVE-2024-5814
Published: Aug 27, 2024
Modified: Aug 27, 2024
PUBLISHED
Description
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500
| Vendor | Product | Versions |
|---|---|---|
wolfSSL | wolfSSL | affected 0 - <= 5.7.0 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now