SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-1793

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to…

MEDIUM 6.5EPSS 62.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 62.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
62.39% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-254
Affected
oracle/supply chain products suite · oracle/jd edwards enterpriseone tools · openssl/openssl · oracle/opus 10g ethernet switch family
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.