CVE-2017-2801
A specially crafted X509 certificate would need to be delivered to the client or server application in order to trigger this vulnerability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate verification issues and abuse. A specially crafted X509 certificate would need to be delivered to the client or server application in order to trigger this vulnerability.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- botan project/botan
- Source
- talos-cna@cisco.com
References
- http://talosintelligence.com/vulnerability_reports/TALOS-2017-0294Exploit, Mitigation, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2017/dsa-3939
- http://www.securityfocus.com/bid/98106Third Party Advisory, US Government Resource
- http://talosintelligence.com/vulnerability_reports/TALOS-2017-0294Exploit, Mitigation, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2017/dsa-3939
- http://www.securityfocus.com/bid/98106Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.