PT-2023-25848 · Wolfssl · Wolfssl

·

CVE-2023-3724

·

Published

2023-07-17

·

Updated

2026-07-14

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description When a TLS 1.3 client connects to a malicious server without receiving a PSK (pre shared key) extension or a KSE (key share extension), it uses a default predictable buffer for the IKM (Input Keying Material) value. This compromises the generated session master secret key, allowing an eavesdropper to reconstruct it and potentially access or meddle with message contents. The issue does not affect client validation of connected servers or expose private key information but could result in an insecure TLS 1.3 session.
Recommendations Update the version of wolfSSL used to resolve the issue. As a temporary workaround, consider restricting connections to trusted servers to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-27649
CVE-2023-3724
JLSEC-2026-676

Affected Products

Wolfssl