CVE-2024-12243
published 2025-02-10CVE-2024-12243: A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.24%
65.9th percentile
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u4 (bookworm) | gnutls28 3.7.9-2+deb12u4 (bookworm) |
| msrc | azl3_gnutls_3.8.3-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-3_on_cbl_mariner_2.0 | — | — |
| ubuntu | gnutls28 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2025-02-20
CVE-2024-12243 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to consume resources if it decoded specially crafted
certificates.
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this issue
to cause GnuTLS to consume resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos
vendor_msrc·2025-02-11·CVSS 5.3
CVE-2024-12243 [MEDIUM] CWE-407 Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos
Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Re
Red Hat
gnutls: GnuTLS Impacted by Inefficient DER Decoding in libtasn1 Leading to Remote DoS
vendor_redhat·2025-02-10·CVSS 5.3
CVE-2024-12243 [MEDIUM] CWE-407 gnutls: GnuTLS Impacted by Inefficient DER Decoding in libtasn1 Leading to Remote DoS
gnutls: GnuTLS Impacted by Inefficient DER Decoding in libtasn1 Leading to Remote DoS
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted cert
Debian
CVE-2024-12243: gnutls28 - A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. ...
vendor_debian·2024·CVSS 5.3
CVE-2024-12243 [MEDIUM] CVE-2024-12243: gnutls28 - A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. ...
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u4)
bullseye: resolved (fixed in 3.7.1-5+deb11u7)
forky: resolved (fixed in 3.8.9-2)
sid: resolved (fixed in 3.8.9-2)
trixie: resolved (fixed in 3.8.9-2)
OSV
CVE-2024-12243: A flaw was found in GnuTLS, which relies on libtasn1 for ASN
osv·2025-02-10·CVSS 5.3
CVE-2024-12243 [MEDIUM] CVE-2024-12243: A flaw was found in GnuTLS, which relies on libtasn1 for ASN
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
GHSA
GHSA-cqj4-fp95-jqxq: A flaw was found in GnuTLS, which relies on libtasn1 for ASN
ghsa_unreviewed·2025-02-10
CVE-2024-12243 [MEDIUM] CWE-407 GHSA-cqj4-fp95-jqxq: A flaw was found in GnuTLS, which relies on libtasn1 for ASN
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2025:17361https://access.redhat.com/errata/RHSA-2025:4051https://access.redhat.com/errata/RHSA-2025:7076https://access.redhat.com/errata/RHSA-2025:8020https://access.redhat.com/errata/RHSA-2025:8385https://access.redhat.com/security/cve/CVE-2024-12243https://bugzilla.redhat.com/show_bug.cgi?id=2344615https://gitlab.com/gnutls/gnutls/-/issues/1553https://gitlab.com/gnutls/libtasn1/-/issues/52https://lists.debian.org/debian-lts-announce/2025/02/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20250523-0002/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-202008.html
2025-02-10
Published