wolfSSL wolfEngine是wolfSSL公司的一款具备加密运算功能的引擎软件。 wolfSSL wolfEngine 1.4.1之前版本存在加密问题漏洞,该漏洞源于生成8字节显式AES-GCM nonce时未递增,导致密钥和nonce重用,可能泄露密钥流和GHASH认证密钥,从而伪造认证标签。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wolfSSL Inc. | wolfEngine | ≤ 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wolfSSL Inc. | wolfEngine | 0 ~ 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81019 | 7.4 HIGH | wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record |
| CVE-2026-81341 | 6.5 MEDIUM | wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records |
No comments yet