CVE-2021-3336
8.1
HIGH
CVSS 3.1
EPSS 0.18%
Description
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.
How to fix CVE-2021-3336
To remediate CVE-2021-3336, upgrade the affected package to a fixed version below.
- Debian/wolfssl—upgrade to 4.6.0-3 or later
Is CVE-2021-3336 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.6.0-3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |