Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gm2-vj3x-997g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 8 лет назад

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

CVSS3: 5.9
debian
больше 8 лет назад

CyaSSL does not check the key usage extension in leaf certificates, wh ...

EPSS

Процентиль: 44%
0.00213
Низкий

5.9 Medium

CVSS3