A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. (CVE-2026-93304)
A vulnerability in (D)TLS 1.2 clients allows acceptance of a ChangeCipherSpec message before sending the ClientKeyExchange. This leads the client to install read keys derived from a known deterministic key, enabling an attacker to complete the handshake and send data accepted as authentic. The attack requires a man-in-the-middle position for certificate-based suites, but PSK connections are vulnerable to any fake server. The client's outgoing traffic remains secure, and the genuine server never completes the handshake. The CVSS score is 3.7, indicating medium severity.
AI Analysis
Technical Summary
CVE-2026-93304 describes a vulnerability in (D)TLS 1.2 clients where the client accepts a ChangeCipherSpec message before sending its ClientKeyExchange. Since no master secret is derived at that point, the client uses read keys from a known deterministic key to verify the server's Finished message. An attacker can exploit this out-of-order ChangeCipherSpec to impersonate the server and send data the client accepts as authentic. This affects DTLS 1.2 clients due to datagram delivery of out-of-order records, and TLS 1.2 clients when wolfSSL_inject() is used or read ahead is enabled. For certificate-based suites, a man-in-the-middle is required; for PSK connections, any fake server can succeed without knowing the PSK. The client's own transmitted data remains secure, and the real server does not complete the handshake.
Potential Impact
The vulnerability allows an attacker to impersonate the server and send data that the client accepts as authentic, compromising data integrity on the client side. However, the attacker cannot decrypt or read the client's outgoing traffic, and the genuine server never completes the handshake. For certificate-based suites, exploitation requires a man-in-the-middle position. For PSK connections, any fake server can exploit the flaw without the PSK. The CVSS score of 3.7 reflects a medium impact primarily on data integrity.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Mitigation should focus on avoiding use of wolfSSL_inject() or read ahead features in TLS 1.2 clients and ensuring proper handling of ChangeCipherSpec messages. Network defenses to prevent man-in-the-middle attacks are also relevant for certificate-based suites.
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. (CVE-2026-93304)
Description
A vulnerability in (D)TLS 1.2 clients allows acceptance of a ChangeCipherSpec message before sending the ClientKeyExchange. This leads the client to install read keys derived from a known deterministic key, enabling an attacker to complete the handshake and send data accepted as authentic. The attack requires a man-in-the-middle position for certificate-based suites, but PSK connections are vulnerable to any fake server. The client's outgoing traffic remains secure, and the genuine server never completes the handshake. The CVSS score is 3.7, indicating medium severity.
CVSS v3.1
Score 3.7low
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93304 describes a vulnerability in (D)TLS 1.2 clients where the client accepts a ChangeCipherSpec message before sending its ClientKeyExchange. Since no master secret is derived at that point, the client uses read keys from a known deterministic key to verify the server's Finished message. An attacker can exploit this out-of-order ChangeCipherSpec to impersonate the server and send data the client accepts as authentic. This affects DTLS 1.2 clients due to datagram delivery of out-of-order records, and TLS 1.2 clients when wolfSSL_inject() is used or read ahead is enabled. For certificate-based suites, a man-in-the-middle is required; for PSK connections, any fake server can succeed without knowing the PSK. The client's own transmitted data remains secure, and the real server does not complete the handshake.
Potential Impact
The vulnerability allows an attacker to impersonate the server and send data that the client accepts as authentic, compromising data integrity on the client side. However, the attacker cannot decrypt or read the client's outgoing traffic, and the genuine server never completes the handshake. For certificate-based suites, exploitation requires a man-in-the-middle position. For PSK connections, any fake server can exploit the flaw without the PSK. The CVSS score of 3.7 reflects a medium impact primarily on data integrity.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Mitigation should focus on avoiding use of wolfSSL_inject() or read ahead features in TLS 1.2 clients and ensuring proper handling of ChangeCipherSpec messages. Network defenses to prevent man-in-the-middle attacks are also relevant for certificate-based suites.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vpg5-xh2g-4x3c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-93304"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac139bba43b0b3b89d69d50
Added to database: 10/03/2026, 17:22:03 UTC
Last enriched: 10/03/2026, 17:43:20 UTC
Last updated: 10/03/2026, 23:40:51 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.