Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.5
CVE-2026-81341
- EPSS 0.2%
- Veröffentlicht 28.08.2026 14:43:43
- Zuletzt bearbeitet 29.09.2026 19:10:08
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-non...
7.4
CVE-2026-81020
- EPSS 0.24%
- Veröffentlicht 28.08.2026 14:42:59
- Zuletzt bearbeitet 29.09.2026 19:10:21
wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key a...
1