CVE-2025-4575Improper Certificate Validation in Openssl

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 77.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateJan 15

Description

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use. A copy & paste error during minor refactoring of the code introduced this issue in the OpenSSL 3.5 version. If, for example, a trusted CA certificate should be trusted only for the purpose of authenticating TLS serv

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LExploitability: 3.9 | Impact: 2.5

Affected Packages9 packages

debiandebian/openssl< openssl 3.5.0-2 (forky)
CVEListV5openssl/openssl3.5.03.5.1
Alpineopenssl/openssl< 3.5.1-r0+1
Debianopenssl/openssl< 3.5.0-2+1
NVDopenssl/openssl3.5.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-v8qh-5c5w-48pp: Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate2025-05-22
OSV
CVE-2025-4575: Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate2025-05-22
OSV
CVE-2025-4575: Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate2025-05-22

📋Vendor Advisories

4
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Server Infrastructure (OpenSSL) — CVE-2025-45752026-01-15
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Security, Porting, Cloud Deployment Architecture (OpenSSL) — CVE-2025-45752025-10-15
Microsoft
The x509 application adds trusted use instead of rejected use2025-05-13
Debian
CVE-2025-4575: openssl - Issue summary: Use of -addreject option with the openssl x509 application adds a...2025
CVE-2025-4575 — Improper Certificate Validation | cvebase