SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityRejected

CVE-2021-3601

OpenSSL does not class this issue as a security vulnerability.

UnscoredEPSS —

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-119646061

CVSS
Not yet scored
EPSS
No score yet
CISA KEV
Not listed
Source
openssl-security@openssl.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.