CVE-2023-2975Improper Validation of Integrity Check Value in Openssl

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 59.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateApr 10

Description

Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding or reordering such empty entries as these are ignored by the OpenSSL implementation. We are currently unaware of any such applications. The AES-SIV algorithm allows for authentic

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages11 packages

debiandebian/openssl< openssl 3.0.10-1~deb12u1 (bookworm)
CVEListV5openssl/openssl3.1.03.1.2+1
Alpineopenssl/openssl< 3.0.9-r2+6
Debianopenssl/openssl< 3.0.10-1~deb12u1+2
Ubuntuopenssl/openssl< 3.0.2-0ubuntu1.12

Patches

🔴Vulnerability Details

4
OSV
openssl vulnerabilities2023-10-24
OSV
CVE-2023-2975: Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a2023-07-14
OSV
CVE-2023-2975: Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a2023-07-14
GHSA
GHSA-hpqg-7fjp-436p: Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a2023-07-14

📋Vendor Advisories

8
CISA ICS
Siemens SIDIS Prime2025-04-10
CISA ICS
Siemens SINEC INS2024-11-14
CISA ICS
Siemens SINEC NMS2024-02-15
CISA ICS
Siemens SIMATIC MV5002023-11-16
Ubuntu
OpenSSL vulnerabilities2023-10-24
CVE-2023-2975 — Openssl vulnerability | cvebase