← All CVEs

CVE-2024-6119

high · 7.5

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.

7.5
CVSS
66.6%
EPSS (exploit prob.)
99th
EPSS percentile
2024-09-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-843

Affected products

VendorProductAffected versions
opensslopenssl>= 3.0.0, < 3.0.15
opensslopenssl>= 3.1.0, < 3.1.7
opensslopenssl>= 3.2.0, < 3.2.3
opensslopenssl>= 3.3.0, < 3.3.2
netappactive_iq_unified_managerall versions
netappmanagement_services_for_element_software_and_netapp_hciall versions
netappontap_9all versions
netappontap_select_deploy_administration_utilityall versions
netappontap_tools9
netappbrocade_fabric_operating_systemall versions
netapph300s_firmwareall versions
netapph300sall versions
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph410c_firmwareall versions
netapph410call versions
netapph610c_firmwareall versions
netapph610call versions
netapph610s_firmwareall versions
netapph610sall versions
netapph615call versions
netapph615c_firmwareall versions
netappbootstrap_osall versions
netapphci_compute_nodeall versions
netappa250_firmwareall versions
netappa250all versions
netapp500f_firmwareall versions
netapp500fall versions
netappc250_firmwareall versions
netappc250all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-6119