$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
● CISA KEV 미등재

CVE-2026-94419

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and C…

낮음2.3악용 확률 0.10%CWE-287공개 2026-09-27
2.329CWE-287

📌 이 취약점에 대해 확인된 사실

전부 발행처가 발표한 값입니다. 우리가 계산하거나 판단한 숫자는 하나도 없습니다.

악용 여부

CISA KEV 목록에 없습니다. 악용이 없다는 증명이 아니라, 미국 정부가 악용을 확인해 등재한 적이 없다는 뜻입니다.

심각도 (발행처 발표값)

낮음2.3

CVSS 버전4.0
평가 기관facts@wolfssl.com

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

악용 확률 (EPSS)

0.1%

30일 내 악용 확률0.10%
전체 CVE 중 백분위0.7%
기준일2026-10-02

🇰🇷 한국어 공식 권고

KISA 보호나라 권고문 본문에서 이 CVE 번호가 발견된 문서입니다.

전체 권고 ›
이 CVE 를 다룬 KISA 보호나라 권고를 아직 찾지 못했습니다. 권고가 없다는 확증은 아닙니다 — 우리는 RSS 로 공개된 최근 공지만 수집합니다.

📄 원문 그대로

아래 문장은 전부 발행처가 쓴 것입니다. 번역하지 않습니다 — 보안 문서의 오역은 조치를 바꿉니다.

취약점 설명 (NVD)

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it against that hash alone. Because the TLS 1.2 session ID is chosen by the server and sent in clear, AddSessionToCache() matches any other server's session on the same ID and overwrites the client-side entry with that server's master secret, cipher suite and version, while the handle continues to resolve; nothing on the write path compares the peer, the application's server ID or the WOLFSSL_CTX. Resuming through the handle then produces an abbreviated handshake in which no Certificate message is sent, so neither chain verification nor wolfSSL_check_domain_name() runs, and the attacker is accepted as the original server for the whole of that connection. Affected builds are those leaving NO_SESSION_CACHE_REF, NO_SESSION_CACHE, NO_CLIENT_CACHE and TITAN_SESSION_CACHE all undefined, which includes a plain ./configure, --enable-opensslextra and --enable-opensslall; fifteen integration options define NO_SESSION_CACHE_REF and are therefore not affected, among them --enable-all, --enable-distro, --enable-curl, --enable-nginx, --enable-haproxy, --enable-stunnel, --enable-wpas and the rest of the OPENSSL_COMPATIBLE_DEFAULTS family, and --enable-leanpsk, --enable-leantls, --enable-lowresource and --enable-tinytls13 disable the cache outright. The application must use the legacy reference flow, wolfSSL_get_session() or SSL_get_session() followed by wolfSSL_set_session(); wolfSSL_get1_session() returns the session object itself and is not affected, nor are wolfSSL_SetServerID() lookups. Only TLS 1.2 and below and DTLS 1.2 and below are reachable, since TLS 1.3 and ticket resumption with an empty ServerHello session ID both use a client-chosen cache key. The poisoned entry lives in the process-global cache, so it crosses WOLFSSL_CTX boundaries and persists until the entry is evicted or the session times out, 500 seconds by default. Releases v5.3.0 through v5.9.2 are affected; the fix adds a per-write generation counter to the cache and raises WOLFSSL_CACHE_VERSION from 2 to 3, so a cache persisted by an older build is rejected by a fixed one.

약점 유형(CWE):CWE-287

참조 문서 1건 · NVD 분석 상태 Awaiting Analysis · 수집 2026-09-29

참고

이 취약점은 CISA KEV 에 등재되지 않아 CISA 원문이 없습니다. 영향 범위와 패치 버전은 제품 버전·구성에 따라 다르므로 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.

악용 확률 변화

우리가 매일 저장한 EPSS 스냅샷입니다. 원본은 전날 값만 주므로, 이 표는 수집을 시작한 이후만 보여줍니다.

기준일확률백분위
2026-10-020.10%0.7%
2026-10-010.10%0.7%
2026-09-290.08%0.1%
이 페이지는 조치 지시가 아닙니다. 영향 범위와 패치 버전은 제품·구성에 따라 다르므로, 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.