CVE-2024-12797
published 2025-02-11CVE-2024-12797: Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because…
PriorityP337medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
2.44%
82.5th percentile
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
server may fail to notice that the server was not authenticated, because
handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode
is set.
Impact summary: TLS and DTLS connections using raw public keys may be
vulnerable to man-in-middle attacks when server authentication failure is not
detected by clients.
RPKs are disabled by default in both TLS clients and TLS servers. The issue
only arises when TLS clients explicitly enable RPK use by the server, and the
server, likewise, enables sending of an RPK instead of an X.509 certificate
chain. The affected clients are those that then rely on the handshake to
fail when the server's RPK fails to match one of the expected public keys,
by setting the verification mode to SSL_VERIFY_PEER.
Clients that enable server-side raw public keys can still find out that raw
public key verification failed by calling SSL_get_verify_result(), and those
that do, and take appropriate action, are not affected. This issue was
introduced in the initial implementation of RPK support in OpenSSL 3.2.
The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryptography.io | cryptography | >= 42.0.0 < 44.0.1 | 44.0.1 |
| debian | openssl | < openssl 3.4.1-1 (forky) | openssl 3.4.1-1 (forky) |
| msrc | azl3_cloud-hypervisor-cvm_38.0.72.2-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_cloud-hypervisor-cvm_41.0.79-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_cloud-hypervisor_41.0.139-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240524git3e722403cd16-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssl_3.3.2-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssl_3.3.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-cryptography_42.0.5-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-17_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-16_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.86.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-hypervisor-cvm_38.0.72.2-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cloud-hypervisor_32.0-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_edk2_20230301gitf80f052277c8-41_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hvloader_1.0.1-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_openssl_1.1.1k-36_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rust_1.72.0-10_on_cbl_mariner_2.0 | — | — |
| openssl | openssl | >= 0 < 3.3.3-r0 | 3.3.3-r0 |
| openssl | openssl | >= 0 < 3.3.3-r0 | 3.3.3-r0 |
| openssl | openssl | >= 0 < 3.3.3-r0 | 3.3.3-r0 |
| openssl | openssl | >= 0 < 3.3.3-r0 | 3.3.3-r0 |
| openssl | openssl | >= 0 < 3.4.1-1 | 3.4.1-1 |
| openssl | openssl | >= 0 < 3.4.1-1 | 3.4.1-1 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_debian6.3LOW
vendor_msrc6.3MEDIUM
vendor_oracle6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Cryptography) — CVE-2024-12797
vendor_oracle·2025-10-15·CVSS 6.3
CVE-2024-12797 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Analytics Server (Cryptography) — CVE-2024-12797
Oracle Oracle Analytics Risk Matrix: Analytics Server (Cryptography) vulnerability
CVE: CVE-2024-12797
CVSS: 6.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Alarms, KPI, and Measurements (Cryptography) — CVE-2024-12797
vendor_oracle·2025-07-15·CVSS 6.3
CVE-2024-12797 [MEDIUM] Oracle Oracle Communications Risk Matrix: Alarms, KPI, and Measurements (Cryptography) — CVE-2024-12797
Oracle Oracle Communications Risk Matrix: Alarms, KPI, and Measurements (Cryptography) vulnerability
CVE: CVE-2024-12797
CVSS: 6.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Cryptography) — CVE-2024-12797
vendor_oracle·2025-04-15·CVSS 6.3
CVE-2024-12797 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Cryptography) — CVE-2024-12797
Oracle Oracle Communications Risk Matrix: Configuration (Cryptography) vulnerability
CVE: CVE-2024-12797
CVSS: 6.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
It was discovered that OpenSSL clients incorrectly handled authenticating
servers using RFC7250 Raw Public Keys. In certain cases, the connection
will not abort as expected, possibly causing the communication to be
intercepted. (CVE-2024-12797)
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker
Red Hat
openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected
vendor_redhat·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] CWE-295 openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected
openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
server may fail to notice that the server was not authenticated, because
handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode
is set.
Impact summary: TLS and DTLS connections using raw public keys may be
vulnerable to man-in-middle attacks when server authentication failure is not
detected by clients.
RPKs are disabled by default in both TLS clients and TLS servers. The issue
only arises when TLS clients explicitly enable RPK use by the server, and the
server, likewise, enables sending of an RPK instead of an X.509 certificate
chain. The affected clients are those that then rely on the handshake to
fail when
Microsoft
RFC7250 handshakes with unauthenticated servers don't abort as expected
vendor_msrc·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] CWE-392 RFC7250 handshakes with unauthenticated servers don't abort as expected
RFC7250 handshakes with unauthenticated servers don't abort as expected
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refe
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Debian
CVE-2024-12797: openssl - Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a se...
vendor_debian·2024·CVSS 6.3
CVE-2024-12797 [MEDIUM] CVE-2024-12797: openssl - Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a se...
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. Impact summary: TLS and DTLS connections using raw public keys may be vulnerable to man-in-middle attacks when server authentication failure is not detected by clients. RPKs are disabled by default in both TLS clients and TLS servers. The issue only arises when TLS clients explicitly enable RPK use by the server, and the server, likewise, enables sending of an RPK instead of an X.509 certificate chain. The affected clients are those that then rely on the handshake to fail when the server's RPK fails to match one of the expected public keys, by setting the v
VulDB
OpenSSL up to 3.4.0 RFC7250 Raw Public Key error condition (Nessus ID 216104 / WID-SEC-2025-1850)
vuldb·2026-04-10·CVSS 6.3
CVE-2024-12797 [MEDIUM] OpenSSL up to 3.4.0 RFC7250 Raw Public Key error condition (Nessus ID 216104 / WID-SEC-2025-1850)
A vulnerability, which was classified as problematic, has been found in OpenSSL up to 3.4.0. This affects an unknown part of the component RFC7250 Raw Public Key Handler. Performing a manipulation results in missing report of error condition.
This vulnerability is known as CVE-2024-12797. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
OSV
CVE-2024-12797: Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because
osv·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] CVE-2024-12797: Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. Impact summary: TLS and DTLS connections using raw public keys may be vulnerable to man-in-middle attacks when server authentication failure is not detected by clients. RPKs are disabled by default in both TLS clients and TLS servers. The issue only arises when TLS clients explicitly enable RPK use by the server, and the server, likewise, enables sending of an RPK instead of an X.509 certificate chain. The affected clients are those that then rely on the handshake to fail when the server's RPK fails to match one of the expected public keys, by setting the v
OSV
CVE-2024-12797: Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
server may fail to notice that the server was not authenticated, because
osv·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] CVE-2024-12797: Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
server may fail to notice that the server was not authenticated, because
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
server may fail to notice that the server was not authenticated, because
handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode
is set.
Impact summary: TLS and DTLS connections using raw public keys may be
vulnerable to man-in-middle attacks when server authentication failure is not
detected by clients.
RPKs are disabled by default in both TLS clients and TLS servers. The issue
only arises when TLS clients explicitly enable RPK use by the server, and the
server, likewise, enables sending of an RPK instead of an X.509 certificate
chain. The affected clients are those that then rely on the handshake to
fail when the server's RPK fails to match one of the expected public keys,
by setting the
GHSA
Vulnerable OpenSSL included in cryptography wheels
ghsa·2025-02-11
CVE-2024-12797 [LOW] CWE-1395 Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt.
If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.
OSV
openssl vulnerabilities
osv·2025-02-11·CVSS 6.3
CVE-2024-12797 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
It was discovered that OpenSSL clients incorrectly handled authenticating
servers using RFC7250 Raw Public Keys. In certain cases, the connection
will not abort as expected, possibly causing the communication to be
intercepted. (CVE-2024-12797)
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker could use this issue to cause OpenSSL to crash,
resulting in a d
OSV
Vulnerable OpenSSL included in cryptography wheels
osv·2025-02-11
CVE-2024-12797 [LOW] Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt.
If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.
No detection rules found.
No public exploits indexed.
https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699https://openssl-library.org/news/secadv/20250211.txthttp://www.openwall.com/lists/oss-security/2025/02/11/3http://www.openwall.com/lists/oss-security/2025/02/11/4https://security.netapp.com/advisory/ntap-20250214-0001/
2025-02-11
Published