The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Jul 10, 2015 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Jul 9, 2015 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jul 9, 2015 |
| Freebsd | — | Upgrade opensslUpgrade mingw32-openssl | Dec 10, 2025 | Jul 9, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Jul 9, 2015 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 26, 2016 | Jul 9, 2015 |
| Hpux | — | Update openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-CER to the latest version | Aug 11, 2017 | Jul 9, 2015 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | May 3, 2018 | Jul 9, 2015 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.1.16-0.175.2.13.0.3.0 on Solaris 11.2Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.13.0.3.0 on Solaris 11.2 | May 29, 2017 | Jul 9, 2015 |
| Suse | — | Upgrade libmysql55client_r18-x86Upgrade openssl-1_0_0Upgrade libopenssl-1_0_0-develUpgrade opensslUpgrade libmysql55client_r18-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1Upgrade mysql-clientUpgrade libmysql55client18Upgrade libopenssl1_0_0Upgrade libopenssl-1_1-develUpgrade libopenssl10Upgrade mysqlUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-develUpgrade libopenssl1_1-hmacUpgrade openssl-1_1Upgrade libmysql55client_r18Upgrade libmysql55client18-32bitUpgrade mysql-toolsUpgrade libmysql55client18-x86Upgrade libopenssl1_1-32bit | Dec 18, 2015 | Jul 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub