SB2022010405 - MitM attack in wolfSSL 



SB2022010405 - MitM attack in wolfSSL

Published: January 4, 2022

Security Bulletin ID SB2022010405
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use of insufficiently random values (CVE-ID: N/A)

The vulnerability allows a remote attacker to decrypt TLS session.

The vulnerability exists in wolfSSL implementation when using AES-CBC or DES3 with TLS/DTLS 1.2 or 1.1. The initialization vector used is not random, which may allow an attacker to decrypt the TLS session or perform MitM attack.


Remediation

Install update from vendor's website.