CVE-2014-2903: wolfSSL

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

Affected products

  • wolfSSL wolfSSL: up to and including 2.9.4

Published 2017-10-06. Last modified 2026-06-17.