CVE-2021-44718
MEDIUMWolfssl < 5.0.0 - Infinite Loop
Title source: ruleDescription
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers.
Scores
CVSS v3
5.9
EPSS
0.0021
EPSS Percentile
42.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (1)
wolfssl/wolfssl
< 5.0.0
Published
Sep 02, 2022
Tracked Since
Feb 18, 2026