CVE-2021-46880
published 2023-04-15CVE-2021-46880: x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.57%
43.3th percentile
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | libressl | < 3.4.2 | 3.4.2 |
| openbsd | openbsd | < 7.0 | 7.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.4.2-relnotes.txthttps://ftp.openbsd.org/pub/OpenBSD/patches/7.0/common/006_x509.patch.sighttps://github.com/openbsd/src/commit/3f851282810fa0ab4b90b3b1ecec2e8717ef16f8https://security.netapp.com/advisory/ntap-20230517-0006/https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.4.2-relnotes.txthttps://ftp.openbsd.org/pub/OpenBSD/patches/7.0/common/006_x509.patch.sighttps://github.com/openbsd/src/commit/3f851282810fa0ab4b90b3b1ecec2e8717ef16f8https://security.netapp.com/advisory/ntap-20230517-0006/
2023-04-15
Published