Lucene search

K
osvGoogleOSV:CVE-2022-25638
HistoryFeb 24, 2022 - 3:15 p.m.

CVE-2022-25638

2022-02-2415:15:32
Google
osv.dev
4
wolfssl
certificate validation
tls 1.3

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

42.9%

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

42.9%

Related for OSV:CVE-2022-25638