CVE-2025-15346
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
08/01/2026
Última modificación:
08/01/2026
Descripción
*** Pendiente de traducción *** A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced. <br />
<br />
Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was verified if presented, but connections were incorrectly authenticated when no client certificate was provided. <br />
<br />
This results in improper authentication, allowing attackers to bypass mutual TLS (mTLS) client authentication by omitting a client certificate during the TLS handshake. <br />
<br />
The issue affects versions up to and including 5.8.2.
Impacto
Puntuación base 4.0
9.30
Gravedad 4.0
CRÍTICA



