CVE-2025-9230
published 2025-09-30CVE-2025-9230: Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.74%
75.2th percentile
Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write.
Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for an application. The out-of-bounds write can cause
a memory corruption which can have various consequences including
a Denial of Service or Execution of attacker-supplied code.
Although the consequences of a successful exploit of this vulnerability
could be severe, the probability that the attacker would be able to
perform it is low. Besides, password based (PWRI) encryption support in CMS
messages is very rarely used. For that reason the issue was assessed as
Moderate severity according to our Security Policy.
The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.0.17-1~deb12u3 (bookworm) | openssl 3.0.17-1~deb12u3 (bookworm) |
| msrc | azl3_cloud-hypervisor_41.0.139-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240524git3e722403cd16-9_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssl_3.3.3-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-19_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-hypervisor-cvm_38.0.72.2-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_openssl_1.1.1k-36_on_cbl_mariner_2.0 | — | — |
| openssl | openssl | >= 0 < 3.0.19-r0 | 3.0.19-r0 |
| openssl | openssl | >= 0 < 3.1.8-r1 | 3.1.8-r1 |
| openssl | openssl | >= 0 < 3.3.5-r0 | 3.3.5-r0 |
| openssl | openssl | >= 0 < 3.3.5-r0 | 3.3.5-r0 |
| openssl | openssl | >= 0 < 3.5.4-r0 | 3.5.4-r0 |
| openssl | openssl | >= 0 < 3.5.4-r0 | 3.5.4-r0 |
| openssl | openssl | >= 0 < 1.1.1w-0+deb11u4 | 1.1.1w-0+deb11u4 |
| openssl | openssl | >= 0 < 3.0.17-1~deb12u3 | 3.0.17-1~deb12u3 |
| openssl | openssl | >= 0 < 3.5.1-1+deb13u1 | 3.5.1-1+deb13u1 |
| openssl | openssl | >= 0 < 3.5.4-1 | 3.5.4-1 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.20 | 3.0.2-0ubuntu1.20 |
| openssl | openssl | >= 0 < 3.0.13-0ubuntu3.6 | 3.0.13-0ubuntu3.6 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm11 | 1.0.1f-1ubuntu2.27+esm11 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.20+esm13 | 1.0.2g-1ubuntu4.20+esm13 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIDIS Prime
cisa_ics·2026-03-12·CVSS 7.5
[HIGH] Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateMarch 12, 2026
Alert CodeICSA-26-071-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS Prime and recommends to update to the latest version.
The following versions of Siemens SIDIS Prime are affected:
- SIDIS Prime vers:intdot/<4.0.800 (CVE-2024-29857, CVE-2024-30171, CVE-2024-30172, CVE-2024-41996, CVE-2025-6965, CVE-2025-7783, CVE-2025-9230, CVE-2025-9232, CVE-2025-9670, CVE-2025-12816, CVE-2025-15284, CVE-2025-58751, CVE-2025-58752, CVE-2025-58754, CVE-202
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (OpenSSL) — CVE-2025-9230
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-9230 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (OpenSSL) — CVE-2025-9230
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (OpenSSL) vulnerability
CVE: CVE-2025-9230
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Red Hat
openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
vendor_redhat·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] CWE-787 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write.
Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for an application. The out-of-bounds write can cause
a memory corruption which can have various consequences including
a Denial of Service or Execution of attacker-supplied code.
Although the consequences of a successful exploit of this vulnerability
could be severe, the probability that the attacker would be able to
perform it is low. Besides, password based (PWRI) encryption support in CMS
messages is very rarely used. For that reason the issue was assessed as
Moderate severity according to
BSD
FreeBSD-SA-25:08.openssl: Multiple vulnerabilities in OpenSSL
bsd_advisories·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] FreeBSD-SA-25:08.openssl: Multiple vulnerabilities in OpenSSL
FreeBSD-SA-25:08.openssl Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSL
Category: contrib
Module: openssl
Announced: 2025-09-30
Credits: Stanislav Fort (Aisle Research)
Affects: All supported versions of FreeBSD.
Corrected: 2025-09-30 15:26:14 UTC (stable/15, 15.0-ALPHA4)
2025-09-30 15:28:38 UTC (stable/14, 14.3-STABLE)
2025-09-30 15:37:16 UTC (releng/14.3, 14.3-RELEASE-p4)
2025-09-30 15:37:25 UTC (releng/14.2, 14.2-RELEASE-p7)
2025-09-30 15:30:02 UTC (stable/13, 13.5-STABLE)
2025-09-30 15:37:35 UTC (releng/13.5, 13.5-RELEASE-p5)
CVE Name: CVE-2025-9230, CVE-2025-9231, CVE-2025-9232
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2025-09-30·CVSS 7.5
CVE-2025-9232 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)
Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)
Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This i
Microsoft
Out-of-bounds read & write in RFC 3211 KEK Unwrap
vendor_msrc·2025-09-09·CVSS 7.5
CVE-2025-9230 [HIGH] CWE-125 Out-of-bounds read & write in RFC 3211 KEK Unwrap
Out-of-bounds read & write in RFC 3211 KEK Unwrap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.m
Debian
CVE-2025-9230: openssl - Issue summary: An application trying to decrypt CMS messages encrypted using pas...
vendor_debian·2025·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230: openssl - Issue summary: An application trying to decrypt CMS messages encrypted using pas...
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2,
OSV
CVE-2025-9230: Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write
osv·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230: Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2,
OSV
CVE-2025-9230: Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write
osv·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230: Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write
Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write.
Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for an application. The out-of-bounds write can cause
a memory corruption which can have various consequences including
a Denial of Service or Execution of attacker-supplied code.
Although the consequences of a successful exploit of this vulnerability
could be severe, the probability that the attacker would be able to
perform it is low. Besides, password based (PWRI) encryption support in CMS
messages is very rarely used. For that reason the issue was assessed as
Moderate severity according to our Security Policy.
The FIPS modules in 3.5, 3.4, 3.3, 3
OSV
openssl, openssl1.0 vulnerabilities
osv·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)
Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)
Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-9232)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-9230 mingw-openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
bugzilla·2025-10-01·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230 mingw-openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
CVE-2025-9230 mingw-openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all b
Bugzilla
CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
bugzilla·2025-10-01·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug report
Bugzilla
CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
bugzilla·2025-09-17·CVSS 7.5
CVE-2025-9230 [HIGH] CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
CVE-2025-9230 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
Issue summary: An application trying to decrypt CMS messages encrypted using
password based encryption can trigger an out-of-bounds read and write.
Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for an application. The out-of-bounds write can cause
a memory corruption which can have various consequences including
a Denial of Service or Execution of attacker-supplied code.
Although the consequences of a successful exploit of this vulnerability
could be severe, the probability that the attacker would be able to
perform it is low. Besides, password based (PWRI) encryption support in CMS
messages is very rarely used. For that reason the issue was assessed as
Moderate severi
https://github.com/openssl/openssl/commit/5965ea5dd6960f36d8b7f74f8eac67a8eb8f2b45https://github.com/openssl/openssl/commit/9e91358f365dee6c446dcdcdb01c04d2743fd280https://github.com/openssl/openssl/commit/a79c4ce559c6a3a8fd4109e9f33c1185d5bf2defhttps://github.com/openssl/openssl/commit/b5282d677551afda7d20e9c00e09561b547b2dfdhttps://github.com/openssl/openssl/commit/bae259a211ada6315dc50900686daaaaaa55f482https://github.openssl.org/openssl/extended-releases/commit/c2b96348bfa662f25f4fabf81958ae822063dae3https://github.openssl.org/openssl/extended-releases/commit/dfbaf161d8dafc1132dd88cd48ad990ed9b4c8bahttps://openssl-library.org/news/secadv/20250930.txthttp://www.openwall.com/lists/oss-security/2025/09/30/5https://lists.debian.org/debian-lts-announce/2025/10/msg00001.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-089022.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-253495.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-485750.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-585531.html
2025-09-30
Published