CVE-2018-9127 describes a critical vulnerability in Botan versions 2.2.0 through 2.4.0, where the library incorrectly validated wildcard certificates, potentially allowing them to match hostnames they shouldn't according to RFC 6125. This flaw could enable an attacker with a wildcard certificate for a domain to impersonate other hosts within that same domain. The vulnerability carries a CVSS score of 9.8 (Critical), indicating a severe risk due to its network-based attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While the EPSS score is low, the FAUCET Risk Score is high at 77/100. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a lack of widespread public awareness or active threat actor interest at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, <= 2.4.0CPE matchmatch criteria | cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.