Skip to content

CVE-2014-2900

wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0029 (0.3%)
Percentil: 51.9%
EPSS: 2026-05-06

Afecta

yassl:cyassl

Descripción técnica

wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.

Publicada: 22/4/2014, 14:23:36
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo