Impact
GnuTLS version 3.8.13 contains a flaw that causes the library to accept certificates whose extensions do not comply with RFC standards. This weakness (CWE-295) allows an untrusted or compromised certificate to be treated as valid, effectively bypassing the intended authentication checks. This weakness does not allow arbitrary code execution but permits an attacker to masquerade as a legitimate server or client, enabling impersonation or man‑in‑the‑middle scenarios.
Affected Systems
All installations that use GnuTLS 3.8.13 as part of their TLS stack are susceptible. This includes any software that links with that library for either client or server functionality, regardless of the programming language or platform.
Risk and Exploitability
The CVSS score is 9.1, and the EPSS score is not available. Based on the description, it is inferred that an attacker who can supply a forged certificate during the TLS handshake has a high likelihood of success. The likely attack vector is remote, requiring only the ability to influence the certificate presented in the handshake. While the vulnerability is not listed in the CISA KEV catalog, the potential for impersonation or man‑in‑the‑middle attacks remains high.
OpenCVE Enrichment