#VU55288 Security features bypass in wolfSSL
Published: July 25, 2021
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper validation of OCSP checks, when processing responses for a certificate with no relation to the chain in question and that response contains the NoCheck extension which effectively disables ALL verification of that one cert. A remote attacker can bypass implemented OCSP checks and gain unauthorized access to the system that relies on OCSP verification.