PT-2026-99514 · Wolfssl · Wolfssl
CVE-2026-93304
·
Published
2026-09-27
·
Updated
2026-09-27
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
A (D)TLS 1.2 client may accept a ChangeCipherSpec message before sending its ClientKeyExchange. Since no master secret is derived at this stage, the client uses read keys derived from a known deterministic key to verify the server's Finished message. An attacker can exploit this out-of-order message to impersonate the server and send data that the client accepts as authentic. While the client's outgoing traffic remains encrypted with correct keys, the genuine server never completes the handshake. DTLS 1.2 clients are vulnerable due to the nature of datagram reads, while TLS 1.2 clients are vulnerable if the application uses the
wolfSSL inject() function or enables read ahead. For certificate suites, a man-in-the-middle position is required; for PSK (Pre Shared Key) connections, a fake server can succeed without knowing the PSK.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl