CVE-2023-0401
published 2023-02-08CVE-2023-0401: A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.85%
76.7th percentile
A NULL pointer can be dereferenced when signatures are being
verified on PKCS7 signed or signedAndEnveloped data. In case the hash
algorithm used for the signature is known to the OpenSSL library but
the implementation of the hash algorithm is not available the digest
initialization will fail. There is a missing check for the return
value from the initialization function which later leads to invalid
usage of the digest API most likely leading to a crash.
The unavailability of an algorithm can be caused by using FIPS
enabled configuration of providers or more commonly by not loading
the legacy provider.
PKCS7 data is processed by the SMIME library calls and also by the
time stamp (TS) library calls. The TLS implementation in OpenSSL does
not call these functions however third party applications would be
affected if they call these functions to verify signatures on untrusted
data.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.0.8-1 (bookworm) | openssl 3.0.8-1 (bookworm) |
| nodejs | nodejs | >= 0 < 12.22.9~dfsg-1ubuntu3.3 | 12.22.9~dfsg-1ubuntu3.3 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-1 | 3.0.8-1 |
| openssl | openssl | >= 0 < 3.0.8-1 | 3.0.8-1 |
| openssl | openssl | >= 0 < 3.0.8-1 | 3.0.8-1 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.21 | 1.1.1-1ubuntu2.1~18.04.21 |
| openssl | openssl | >= 0 < 1.1.1f-1ubuntu2.17 | 1.1.1f-1ubuntu2.17 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.8 | 3.0.2-0ubuntu1.8 |
| openssl | openssl | >= 3.0.0 < 3.0.8 | 3.0.8 |
| openssl | openssl | 3.0.0 – 3.0.7 | — |
| paloalto | cortex_data | — | — |
| paloalto | cortex_xdr | — | — |
| paloalto | cortex_xpanse | — | — |
| paloalto | cortex_xsoar | — | — |
| paloalto | globalprotect | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| paloalto | prisma_cloud | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy PCU400
cisa_ics·2025-03-06
Hitachi Energy PCU400
ICS Advisory
##
Hitachi Energy PCU400
Release DateMarch 06, 2025
Alert CodeICSA-25-065-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: PCU400, PCULogger
- Vulnerabilities: Access of Resource Using Incompatible Type ('Type Confusion'), NULL Pointer Dereference, Use After Free, Double Free, Observable Discrepancy, Out-of-bounds Read
## 2. RISK EVALUATION
Exploitation of these vulnerabilities could allow an attacker to access or decrypt sensitive data, crash the device application, or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hita
Oracle
Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) — CVE-2023-0401
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2023-0401 [HIGH] Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) — CVE-2023-0401
Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) vulnerability
CVE: CVE-2023-0401
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2024-01-03·CVSS 5.9
CVE-2022-4450 [MEDIUM] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
Hubert Kario discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2022-4304)
CarpetFuzz, Dawei Wang discovered that Node.js incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-4450)
Octavio Galland and Marcel Böhme discovered that Node.js incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input fi
CISA ICS
Siemens SCALANCE Family Products
cisa_ics·2023-11-16
Siemens SCALANCE Family Products
ICS Advisory
##
Siemens SCALANCE Family Products
Release DateNovember 16, 2023
Alert CodeICSA-23-320-08
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XB-200/XC-200/XP-200/XF-200BA/XR-300WG Family
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, NULL Pointer Dereference, Allocation of Resources Without Limits or Thrott
CISA ICS
ICONICS and Mitsubishi Electric Products
cisa_ics·2023-08-17·CVSS 7.5
[HIGH] ICONICS and Mitsubishi Electric Products
ICS Advisory
##
ICONICS and Mitsubishi Electric Products
Release DateAugust 17, 2023
Alert CodeICSA-23-229-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.9
- ATTENTION: Exploitable remotely
- Vendor: ICONICS, Mitsubishi Electric
- Equipment: ICONICS Product Suite
- Vulnerabilities: Buffer Overflow, Out-of-Bounds Read, Observable Timing Discrepancy, Double Free, and NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in information disclosure, denial-of-service, or remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
ICONICS reports these vulnerabilities affect the following products using OpenSSL:
-
ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI:
Palo Alto
PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
vendor_paloalto·2023-02-08·CVSS 4.9
CVE-2023-0286 [MEDIUM] PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSL vulnerabilities that were disclosed on February 7, 2023 (CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, and CVE-2023-0401) as it relates to our products. At this time, there are no demonstrated scenarios that enable successful
CVEs: CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401
Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
Red Hat
openssl: NULL dereference during PKCS7 data verification
vendor_redhat·2023-02-07·CVSS 7.5
CVE-2023-0401 [HIGH] openssl: NULL dereference during PKCS7 data verification
openssl: NULL dereference during PKCS7 data verification
A NULL pointer can be dereferenced when signatures are being
verified on PKCS7 signed or signedAndEnveloped data. In case the hash
algorithm used for the signature is known to the OpenSSL library but
the implementation of the hash algorithm is not available the digest
initialization will fail. There is a missing check for the return
value from the initialization function which later leads to invalid
usage of the digest API most likely leading to a crash.
The unavailability of an algorithm can be caused by using FIPS
enabled configuration of providers or more commonly by not loading
the legacy provider.
PKCS7 data is processed by the SMIME library calls and also by the
time stamp (TS) library calls. The TLS implementation in OpenSSL
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2023-02-07·CVSS 4.9
CVE-2023-0217 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Corey Bonnell discovered that OpenSSL incorrectly handled X.509 certificate
verification. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4203)
Hubert Kario discovered that OpenSSL had a timing based side channel in the
OpenSSL RSA Decryption implementation. A remote attacker could possibly use
this issue to recover sensitive inform
Debian
CVE-2023-0401: openssl - A NULL pointer can be dereferenced when signatures are being verified on PKCS7 s...
vendor_debian·2023·CVSS 7.5
CVE-2023-0401 [HIGH] CVE-2023-0401: openssl - A NULL pointer can be dereferenced when signatures are being verified on PKCS7 s...
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization function which later leads to invalid usage of the digest API most likely leading to a crash. The unavailability of an algorithm can be caused by using FIPS enabled configuration of providers or more commonly by not loading the legacy provider. PKCS7 data is processed by the SMIME library calls and also by the time stamp (TS) library calls. The TLS implementation in OpenSSL does not call these functions however third party applicat
OSV
nodejs vulnerabilities
osv·2024-01-03·CVSS 5.9
CVE-2022-4304 [MEDIUM] nodejs vulnerabilities
nodejs vulnerabilities
Hubert Kario discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2022-4304)
CarpetFuzz, Dawei Wang discovered that Node.js incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-4450)
Octavio Galland and Marcel Böhme discovered that Node.js incorrectly handled
certain inputs. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a de
OSV
openssl-src contains `NULL` dereference during PKCS7 data verification
osv·2023-02-08
CVE-2023-0401 [HIGH] openssl-src contains `NULL` dereference during PKCS7 data verification
openssl-src contains `NULL` dereference during PKCS7 data verification
A `NULL` pointer can be dereferenced when signatures are being verified on PKCS7 `signed` or `signedAndEnveloped` data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization function which later leads to invalid usage of the digest API most likely leading to a crash. The unavailability of an algorithm can be caused by using FIPS enabled configuration of providers or more commonly by not loading the legacy provider.
PKCS7 data is processed by the SMIME library calls and also by the time stamp (TS) library calls. The TLS imple
GHSA
openssl-src contains `NULL` dereference during PKCS7 data verification
ghsa·2023-02-08
CVE-2023-0401 [HIGH] CWE-476 openssl-src contains `NULL` dereference during PKCS7 data verification
openssl-src contains `NULL` dereference during PKCS7 data verification
A `NULL` pointer can be dereferenced when signatures are being verified on PKCS7 `signed` or `signedAndEnveloped` data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization function which later leads to invalid usage of the digest API most likely leading to a crash. The unavailability of an algorithm can be caused by using FIPS enabled configuration of providers or more commonly by not loading the legacy provider.
PKCS7 data is processed by the SMIME library calls and also by the time stamp (TS) library calls. The TLS imple
OSV
CVE-2023-0401: A NULL pointer can be dereferenced when signatures are being
verified on PKCS7 signed or signedAndEnveloped data
osv·2023-02-08·CVSS 7.5
CVE-2023-0401 [HIGH] CVE-2023-0401: A NULL pointer can be dereferenced when signatures are being
verified on PKCS7 signed or signedAndEnveloped data
A NULL pointer can be dereferenced when signatures are being
verified on PKCS7 signed or signedAndEnveloped data. In case the hash
algorithm used for the signature is known to the OpenSSL library but
the implementation of the hash algorithm is not available the digest
initialization will fail. There is a missing check for the return
value from the initialization function which later leads to invalid
usage of the digest API most likely leading to a crash.
The unavailability of an algorithm can be caused by using FIPS
enabled configuration of providers or more commonly by not loading
the legacy provider.
PKCS7 data is processed by the SMIME library calls and also by the
time stamp (TS) library calls. The TLS implementation in OpenSSL does
not call these functions however third party applic
OSV
CVE-2023-0401: A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data
osv·2023-02-08·CVSS 7.5
CVE-2023-0401 [HIGH] CVE-2023-0401: A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization function which later leads to invalid usage of the digest API most likely leading to a crash. The unavailability of an algorithm can be caused by using FIPS enabled configuration of providers or more commonly by not loading the legacy provider. PKCS7 data is processed by the SMIME library calls and also by the time stamp (TS) library calls. The TLS implementation in OpenSSL does not call these functions however third party applicat
OSV
openssl vulnerabilities
osv·2023-02-07·CVSS 4.9
CVE-2023-0286 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Corey Bonnell discovered that OpenSSL incorrectly handled X.509 certificate
verification. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4203)
Hubert Kario discovered that OpenSSL had a timing based side channel in the
OpenSSL RSA Decryption implementation. A remote attacker could possibly use
this issue to recover sensitive information. (CVE-2022-4304)
Dawei Wang discovered that OpenSSL incor
OSV
`NULL` dereference during PKCS7 data verification
osv·2023-02-07
CVE-2023-0401 `NULL` dereference during PKCS7 data verification
`NULL` dereference during PKCS7 data verification
A `NULL` pointer can be dereferenced when signatures are being
verified on PKCS7 `signed` or `signedAndEnveloped` data. In case the hash
algorithm used for the signature is known to the OpenSSL library but
the implementation of the hash algorithm is not available the digest
initialization will fail. There is a missing check for the return
value from the initialization function which later leads to invalid
usage of the digest API most likely leading to a crash.
The unavailability of an algorithm can be caused by using FIPS
enabled configuration of providers or more commonly by not loading
the legacy provider.
PKCS7 data is processed by the SMIME library calls and also by the
time stamp (TS) library calls. The TLS implementation in OpenSSL
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=d3b6dfd70db844c4499bec6ad6601623a565e674https://security.gentoo.org/glsa/202402-08https://www.openssl.org/news/secadv/20230207.txthttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=d3b6dfd70db844c4499bec6ad6601623a565e674https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003https://security.gentoo.org/glsa/202402-08https://www.openssl.org/news/secadv/20230207.txt
2023-02-08
Published