vendor:
OpenSSL
by:
Exploit Database
8.8
CVSS
HIGH
Parsing Vulnerability
20
CWE
Product Name: OpenSSL
Affected Version From: OpenSSL 1.0.2
Affected Version To: OpenSSL 1.1.1
Patch Exists: Yes
Related CWE: N/A
CPE: 2.3:a:openssl:openssl
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All
2020
OpenSSL ECC Certificate Parsing Vulnerability
This vulnerability allows an attacker to set a fake generator G = Q in an OpenSSL ECC Certificate, which can be used to generate a valid certificate. This can be exploited by an attacker to generate a valid certificate for any domain, allowing them to perform man-in-the-middle attacks.
Mitigation:
It is recommended to update to the latest version of OpenSSL.