CVE-2023-0464
Last modified
CVE-2023-0464 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.. EPSS estimates a 3.66% chance of exploitation in the next 30 days.
Description
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 1.0.2, < 1.0.2zh |
| Openssl | Openssl | >= 1.1.1, < 1.1.1u |
| Openssl | Openssl | >= 3.0.0, < 3.0.9 |
| Openssl | Openssl | >= 3.1.0, < 3.1.1 |
References
- https://www.openssl.org/news/secadv/20230322.txtVendor Advisory
- https://www.openssl.org/news/secadv/20230322.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0464?
How severe is CVE-2023-0464?
How do I fix CVE-2023-0464?
Are you affected by CVE-2023-0464?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
