CVE-2023-0466Improper Certificate Validation in Openssl

Severity
7.5HIGHNVD
NVD5.3OSV7.4OSV5.3
EPSS
0.8%
top 25.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateNov 28

Description

The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However the implementation of the function does not enable the check which allows certificates with invalid or incorrect policies to pass the certificate verification. As suddenly enabling the policy check could break existing deployments it was decided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy() function. Instead the applica

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages16 packages

debiandebian/openssl< openssl 3.0.9-1 (bookworm)+1
NVDopenssl/openssl1.0.21.0.2zh+4
Alpineopenssl/openssl< 3.0.7-r2+13
Debianopenssl/openssl< 1.1.1n-0+deb11u5+6
Ubuntuopenssl/openssl< 1.1.1-1ubuntu2.1~18.04.22+4

Patches

🔴Vulnerability Details

8
OSV
edk2 regression2025-11-28
OSV
edk2 vulnerabilities2025-11-26
OSV
openssl, openssl1.0 vulnerabilities2023-04-25
OSV
CVE-2023-0466: The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification2023-03-28
GHSA
GHSA-pxvj-4wx4-gv6w: The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification2023-03-28

📋Vendor Advisories

16
Ubuntu
EDK II regression2025-11-28
Ubuntu
EDK II vulnerabilities2025-11-26
CISA ICS
Siemens SCALANCE W7002025-02-13
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Siemens SIMATIC and SIPLUS2024-06-13
CVE-2023-0466 — Improper Certificate Validation | cvebase