CVE-2023-0286 PUBLISHED CVSS 6.400000095367432 MEDIUM

X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. When CRL checking is enabled, this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service.

EPSS 88.47% · 99.5th percentile

Risk Scores

CVSS v3.1
6.400000095367432
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:H/E:P/RL:W/RC:C
EPSS Score
88.47%
99.5th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3

Timeline

References

Open in Interactive Console →