cve/2022/CVE-2022-25638.md
2024-05-25 21:48:12 +02:00

699 B

CVE-2022-25638

Description

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.

POC

Reference

No PoCs from references.

Github