CVE Vulnerabilities

CVE-2021-38597

Insufficient Verification of Data Authenticity

Published: Aug 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
WolfsslWolfssl*4.8.1 (excluding)
WolfsslUbuntubionic*
WolfsslUbuntufocal*
WolfsslUbuntuhirsute*
WolfsslUbuntuimpish*
WolfsslUbuntukinetic*
WolfsslUbuntulunar*
WolfsslUbuntumantic*
WolfsslUbuntuoracular*
WolfsslUbuntuplucky*
WolfsslUbuntutrusty*
WolfsslUbuntuxenial*

References