Security Advisory

CVE-2014-2900

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-04-22 14:00:00
Last updated 2024-08-06 10:28:46
Assigner mitre
State PUBLISHED

Description

wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.