VDB
CVE-2023-51440
CVE-2023-51440
PUBLISHED
CVSS 7.5 HIGH
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data.
EPSS 0.37% · 59.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.37%
59.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenSSL | OpenSSL | 3.0.0 |
Exploit Intelligence
- Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. (github-poc)
- Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. (github-poc)
- Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. (github-poc)
- Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. (github-poc)
- Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. (github-poc)
- arturo-b-cmu/cve-2016-20012 (github-poc)
- arturo-b-cmu/cve-2016-20012 (github-poc)
- arturo-b-cmu/cve-2016-20012 (github-poc)
- arturo-b-cmu/cve-2016-20012 (github-poc)
- arturo-b-cmu/cve-2016-20012 (github-poc)
…and 515 more exploits
Timeline
- Jun 28, 2021 PoC Published
- Dec 11, 2021 PoC Published
- Dec 13, 2021 PoC Published
- Dec 18, 2021 PoC Published
- Apr 7, 2022 PoC Published
- Jun 7, 2022 PoC Published
- Sep 16, 2022 PoC Published
- Jun 9, 2023 PoC Published
- Jul 15, 2023 PoC Published
- Oct 5, 2023 PoC Published
- Oct 21, 2023 PoC Published
- Nov 4, 2023 PoC Published
References
- https://cert-portal.siemens.com/productcert/html/ssa-000072.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-602936.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-647068.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-943925.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-753746.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-806742.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-580228.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-716164.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-797296.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-108696.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-871717.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-516818.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-017796.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-543502.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-665034.html advisory
- OpenSSL Advisory vendor-advisory
- 3.0.8 git commit patch
- https://security.gentoo.org/glsa/202402-08 url
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003 url