CVE-2023-0465Improper Certificate Validation in Openssl

Severity
5.3MEDIUMNVD
OSV7.5OSV7.4
EPSS
0.5%
top 33.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateNov 28

Description

Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default b

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages23 packages

debiandebian/openssl< openssl 3.0.9-1 (bookworm)
NVDopenssl/openssl1.0.21.0.2zh+3
Alpineopenssl/openssl< 1.1.1t-r2+9
Debianopenssl/openssl< 1.1.1n-0+deb11u5+3
Ubuntuopenssl/openssl< 1.1.1-1ubuntu2.1~18.04.22+4

Patches

🔴Vulnerability Details

6
OSV
edk2 regression2025-11-28
OSV
edk2 vulnerabilities2025-11-26
OSV
openssl, openssl1.0 vulnerabilities2023-04-25
OSV
CVE-2023-0465: Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks2023-03-28
OSV
CVE-2023-0465: Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks2023-03-28

📋Vendor Advisories

14
Ubuntu
EDK II regression2025-11-28
Ubuntu
EDK II vulnerabilities2025-11-26
CISA ICS
Siemens SCALANCE W7002025-02-13
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Siemens SIMATIC and SIPLUS2024-06-13
CVE-2023-0465 — Improper Certificate Validation | cvebase