Impact
A hostname verification bypass in GnuTLS v3.8.13 allows an attacker to trick the client into accepting a certificate that does not properly match the target host. By exploiting the Common Name fallback mechanism the attacker can gain access to encrypted traffic, effectively turning secure TLS sessions into readable data streams. This compromise undermines confidentiality and can be used for stealthy data exfiltration or tampering.
Affected Systems
The vulnerability affects GnuTLS version 3.8.13. No other vendors or products are explicitly listed, and affected builds appear to be those including the hostname verification logic in that release.
Risk and Exploitability
The CVSS score is not supplied, but the ability to bypass hostname checks suggests a high severity. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, so the exact exploitation likelihood is unclear. The attack surface requires that the victim use GnuTLS 3.8.13 and that the attacker can present a crafted certificate; however, the lack of a mandatory certificate chain check makes the exploitation in the wild plausible.
OpenCVE Enrichment