CVE Vulnerabilities

CVE-2021-37155

Published: Jul 21, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number in the OCSP response.

Affected Software

Name Vendor Start Version End Version
Wolfssl Wolfssl 4.6.0 (including) 4.8.0 (excluding)
Wolfssl Ubuntu bionic *
Wolfssl Ubuntu hirsute *
Wolfssl Ubuntu impish *
Wolfssl Ubuntu kinetic *
Wolfssl Ubuntu lunar *
Wolfssl Ubuntu mantic *
Wolfssl Ubuntu trusty *
Wolfssl Ubuntu xenial *

References