CVE-2014-2903: wolfSSL
Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.
Affected products
- wolfSSL wolfSSL: up to and including 2.9.4
Published 2017-10-06. Last modified 2026-06-17.