{"api_version":"1","generated_at":"2026-07-24T04:32:33+00:00","cve":"CVE-2021-3336","urls":{"html":"https://cve.report/CVE-2021-3336","api":"https://cve.report/api/cve/CVE-2021-3336.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3336","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3336"},"summary":{"title":"CVE-2021-3336","description":"DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-01-29 05:15:00","updated_at":"2021-03-04 21:20:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://github.com/wolfSSL/wolfssl/pull/3676","name":"https://github.com/wolfSSL/wolfssl/pull/3676","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"TLS 1.3: ensure key for signature in CertificateVerify by SparkiDev · Pull Request #3676 · wolfSSL/wolfssl · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.wolfssl.com/docs/security-vulnerabilities","name":"https://www.wolfssl.com/docs/security-vulnerabilities","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"wolfSSL Security Vulnerabilities | wolfSSL Embedded SSL/TLS Library","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3336","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3336","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3336","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wolfssl","cpe5":"wolfssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3336","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wolfssl","cpe5":"wolfssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-3336","qid":"179418","title":"Debian Security Update for wolfssl (CVE-2021-3336)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-3336","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/wolfSSL/wolfssl/pull/3676","refsource":"MISC","name":"https://github.com/wolfSSL/wolfssl/pull/3676"},{"refsource":"CONFIRM","name":"https://www.wolfssl.com/docs/security-vulnerabilities","url":"https://www.wolfssl.com/docs/security-vulnerabilities"}]}},"nvd":{"publishedDate":"2021-01-29 05:15:00","lastModifiedDate":"2021-03-04 21:20:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*","versionEndExcluding":"4.7.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3336","Ordinal":"201302","Title":"CVE-2021-3336","CVE":"CVE-2021-3336","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3336","Ordinal":"1","NoteData":"DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3336","Ordinal":"2","NoteData":"2021-01-28","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3336","Ordinal":"3","NoteData":"2021-02-22","Type":"Other","Title":"Modified"}]}}}