Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-3230

5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-3230

5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
EPSS: Низкий
msrc логотип

CVE-2026-3230

4 месяца назад

Improper key_share validation in TLS 1.3 HelloRetryRequest

EPSS: Низкий
debian логотип

CVE-2026-3230

5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRe ...

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-g3xr-5f55-cf5g

5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-3230

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-3230

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-3230

Improper key_share validation in TLS 1.3 HelloRetryRequest

0%
Низкий
4 месяца назад
debian логотип
CVE-2026-3230

Missing required cryptographic step in the TLS 1.3 client HelloRetryRe ...

CVSS3: 2.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-g3xr-5f55-cf5g

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
0%
Низкий
5 месяцев назад

Уязвимостей на страницу