wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.
Loading...
Loading...
wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.
April 22, 2014
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-2900
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.