CVE-2025-15346
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced.
Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was verified if presented, but connections were incorrectly authenticated when no client certificate was provided.
This results in improper authentication, allowing attackers to bypass mutual TLS (mTLS) client authentication by omitting a client certificate during the TLS handshake.
The issue affects versions up to and including 5.8.2.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 %
Vulnerabilidad de autenticación en servicio remoto (TLS/mTLS) accesible sin privilegios ni interacción. Permite bypass de verificación de certificado cliente, resultando en acceso no autorizado (CWE-287, CWE-306).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-287, CWE-306
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-15346",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-15346",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-08T19:22:43.022302Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "facts@wolfssl.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.3,
"Automatable": "YES",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "facts@wolfssl.com",
"affectedData": [
{
"repo": "https://github.com/wolfSSL/wolfssl-py",
"vendor": "wolfSSL",
"modules": [
"TLS Peer Certificate Verification (CERT_REQUIRED verify mode)"
],
"product": "wolfSSL-py",
"versions": [
{
"status": "affected",
"version": "5.3.0",
"versionType": "python",
"lessThanOrEqual": "5.8.2"
}
],
"platforms": [
"Linux",
"MacOS",
"Windows"
],
"packageName": "wolfssl",
"programFiles": [
"wolfssl/__init__.py"
],
"collectionURL": "https://pypi.org/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-08T00:15:59.393",
"references": [
{
"url": "https://github.com/wolfSSL/wolfssl-py/commit/b4517dece79f682a8f453abce5cfc0b81bae769d",
"source": "facts@wolfssl.com"
},
{
"url": "https://github.com/wolfSSL/wolfssl-py/pull/62",
"source": "facts@wolfssl.com"
},
{
"url": "https://github.com/wolfSSL/wolfssl-py/releases/tag/v5.8.4-stable",
"source": "facts@wolfssl.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "facts@wolfssl.com",
"description": [
{
"lang": "en",
"value": "CWE-287"
},
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced. \n\nBecause the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was verified if presented, but connections were incorrectly authenticated when no client certificate was provided. \n\nThis results in improper authentication, allowing attackers to bypass mutual TLS (mTLS) client authentication by omitting a client certificate during the TLS handshake. \n\nThe issue affects versions up to and including 5.8.2."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el manejo de verify_mode = CERT_REQUIRED en el paquete Python wolfssl (wolfssl-py) causa que los requisitos de certificado de cliente no se apliquen completamente.\n\nDebido a que la bandera WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT no fue incluida, el comportamiento coincidió efectivamente con CERT_OPTIONAL: un certificado de par fue verificado si se presentó, pero las conexiones fueron autenticadas incorrectamente cuando no se proporcionó ningún certificado de cliente.\n\nEsto resulta en una autenticación impropia, permitiendo a los atacantes eludir la autenticación de cliente de TLS mutuo (mTLS) al omitir un certificado de cliente durante el handshake TLS.\n\nEl problema afecta a las versiones hasta la 5.8.2 inclusive."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"sourceIdentifier": "facts@wolfssl.com"
}