libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
2024-03-27T08:15:41.230
2025-07-30T19:42:09.087
Analyzed
2499f714-1537-4658-8207-48ae4bb9eae9
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | haxx | curl | 8.6.0 | Yes |
Operating System | apple | macos | < 12.7.6 | Yes |
Operating System | apple | macos | < 13.6.8 | Yes |
Operating System | apple | macos | < 14.6 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h610c_firmware | - | Yes |
Hardware | netapp | h610c | - | No |
Operating System | netapp | h610s_firmware | - | Yes |
Hardware | netapp | h610s | - | No |
Operating System | netapp | h615c_firmware | - | Yes |
Hardware | netapp | h615c | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | bootstrap_os | - | Yes |
Hardware | netapp | hci_compute_node | - | No |