CVE-2023-5363Incorrect Provision of Specified Functionality in Openssl

Severity
7.5HIGHNVD
OSV5.3
EPSS
4.7%
top 10.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateJun 12

Description

Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact summary: A truncation in the IV can result in non-uniqueness, which could result in loss of confidentiality for some cipher modes. When calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() the provided OSSL_PARAM array is processed after the key and IV have

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages16 packages

debiandebian/openssl< openssl 3.0.11-1~deb12u2 (bookworm)
NVDopenssl/openssl3.0.03.0.12+1
Alpineopenssl/openssl< 3.0.12-r0+6
Debianopenssl/openssl< 3.0.11-1~deb12u2+2
Ubuntuopenssl/openssl< 3.0.2-0ubuntu1.12

Also affects: Debian Linux 12.0

Patches

🔴Vulnerability Details

4
OSV
CVE-2023-5363: Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths2023-10-25
GHSA
GHSA-xw78-pcr6-wrg8: Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths2023-10-25
OSV
CVE-2023-5363: Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths2023-10-25
OSV
openssl vulnerabilities2023-10-24

📋Vendor Advisories

12
CISA ICS
Siemens SIMATIC S7-1500 CPU Family2025-06-12
CISA ICS
Siemens SIDIS Prime2025-04-10
CISA ICS
Siemens SCALANCE W7002025-02-13
CISA ICS
Siemens SINEC NMS2024-11-14
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CVE-2023-5363 — Openssl vulnerability | cvebase