Description
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant across records, so every AES-CCM record within a connection is encrypted under an identical key and nonce pair. Reusing a CCM key and nonce weakens confidentiality (identical keystream across records, so a known record recovers the others) and integrity (authentication tag forgery). Only wolfEngine is affected; wolfProvider is not. AES-GCM under wolfEngine is tracked separately. AES-CCM cipher suites are not enabled by default and must be explicitly selected, which limits exposure. TLS 1.3 and non-TLS use of the cipher are not affected.
Published: 2026-08-28
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

wolfEngine before version 1.4.1 derives the explicit AES‑CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer rather than the TLS sequence number. The result is that every record in a connection is encrypted with the same key/nonce pair, producing an identical keystream. This reuse allows a known plaintext record to reveal the keystream, which can decrypt all other records, and enables authentication tag forgery, breaking integrity. The vulnerability therefore poses a simultaneous confidentiality and integrity risk for any TLS 1.2 or DTLS 1.2 traffic protected with AES‑CCM.

Affected Systems

The flaw affects wolfSSL Inc.’s wolfEngine product only; wolfProvider is not impacted. All releases prior to 1.4.1 are vulnerable. The issue only surfaces when AES‑CCM cipher suites are explicitly enabled on a TLS 1.2 or DTLS 1.2 connection, and it does not affect TLS 1.3 or non‑TLS use of the cipher. Because AES‑CCM suites are not enabled by default, exposure is limited to configurations that deliberately select them.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector is remote: an adversary who can establish TLS 1.2/DTLS 1.2 connections with a server that has AES‑CCM enabled could exploit the nonce reuse to recover encrypted data and forge integrity tags. Because the vulnerable behavior requires explicit cipher suite selection, the attack surface is narrower than a blind default issue, but systems that have enabled AES‑CCM are still at risk until mitigated.

Generated by OpenCVE AI on August 28, 2026 at 16:42 UTC.

Remediation

Vendor Solution

Upgrade to wolfEngine 1.4.1, which sources the explicit AES-CCM nonce from the TLS sequence number. As an interim mitigation do not enable AES-CCM cipher suites, or use TLS 1.3.


OpenCVE Recommended Actions

  • Upgrade wolfEngine to 1.4.1 or later
  • Disallow the use of AES‑CCM cipher suites on TLS 1.2/DTLS 1.2 connections
  • Switch to TLS 1.3, which is unaffected by this flaw

Generated by OpenCVE AI on August 28, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant across records, so every AES-CCM record within a connection is encrypted under an identical key and nonce pair. Reusing a CCM key and nonce weakens confidentiality (identical keystream across records, so a known record recovers the others) and integrity (authentication tag forgery). Only wolfEngine is affected; wolfProvider is not. AES-GCM under wolfEngine is tracked separately. AES-CCM cipher suites are not enabled by default and must be explicitly selected, which limits exposure. TLS 1.3 and non-TLS use of the cipher are not affected.
Title wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
Weaknesses CWE-323
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wolfSSL

Published:

Updated: 2026-08-28T18:17:50.111Z

Reserved: 2026-08-26T18:08:35.979Z

Link: CVE-2026-81341

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T16:18:29.483

Modified: 2026-08-28T16:18:29.483

Link: CVE-2026-81341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:45:03Z

Weaknesses
  • CWE-323

    Reusing a Nonce, Key Pair in Encryption