PT-2024-6326 · Wolfssl+2 · Wolfssl+2

·

CVE-2024-5814

·

Published

2024-06-06

·

Updated

2026-07-14

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WolfSSL (affected versions not specified)
Description A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. The issue is related to the implementation of the TLS protocol in the WolfSSL library, which is associated with access control deficiencies.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12644
BDU:2024-07277
CVE-2024-5814
JLSEC-2026-684

Affected Products

Alt Linux
Debian
Wolfssl