VDB
CVE-2024-53846
CVE-2024-53846
PUBLISHED
CVSS 5.5 MEDIUM
OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27.0, resulting in a server or client verifying the peer when incorrect extended key usage is presented (i.e., a server will verify a client if they have server auth ext key usage and vice versa).
EPSS 0.26% · 16.5th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
EPSS Score
0.26%
16.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| erlang | otp | 0 |
| erlang | otp | >= 25.3.2.8, <= 25.3.2.16, >= 26.2, <= 26.2.5.6, >= 27.0, <= 27.1.3 |
Timeline
- Jan 21, 1970 Security Advisory
- Dec 5, 2024 CVE Published
- Dec 5, 2024 PoC Published
- Dec 7, 2024 EPSS Score
- Dec 22, 2024 Coalition ESS Score
- Dec 24, 2024 EPSS Score
- Jan 11, 2025 EPSS Score
- Jan 28, 2025 EPSS Score
- Feb 14, 2025 EPSS Score
- Feb 20, 2025 Coalition ESS Score
- Mar 3, 2025 EPSS Score
- Mar 21, 2025 EPSS Score