CVE Vulnerabilities

CVE-2021-38597

Insufficient Verification of Data Authenticity

Published: Aug 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Wolfssl Wolfssl * 4.8.1 (excluding)
Wolfssl Ubuntu bionic *
Wolfssl Ubuntu hirsute *
Wolfssl Ubuntu impish *
Wolfssl Ubuntu kinetic *
Wolfssl Ubuntu lunar *
Wolfssl Ubuntu mantic *
Wolfssl Ubuntu trusty *
Wolfssl Ubuntu xenial *

References