The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Jul 10, 2015 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Jul 9, 2015 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jul 9, 2015 |
| Freebsd | — | Upgrade mingw32-opensslUpgrade openssl | Dec 10, 2025 | Jul 9, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Jul 9, 2015 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 26, 2016 | Jul 9, 2015 |
| Hpux | — | Update openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-LIB to the latest version | Aug 11, 2017 | Jul 9, 2015 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | May 3, 2018 | Jul 9, 2015 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.1.16-0.175.2.13.0.3.0 on Solaris 11.2Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.13.0.3.0 on Solaris 11.2 | May 29, 2017 | Jul 9, 2015 |
| Suse | — | Upgrade libopenssl1_1Upgrade opensslUpgrade libopenssl-1_0_0-develUpgrade libmysql55client18Upgrade libmysql55client_r18-x86Upgrade libmysql55client_r18-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_0_0Upgrade openssl-1_0_0Upgrade mysql-clientUpgrade libopenssl1_1-hmacUpgrade libopenssl10Upgrade libmysql55client_r18Upgrade openssl-1_1Upgrade libmysql55client18-32bitUpgrade libopenssl-1_1-develUpgrade libopenssl1_1-32bitUpgrade mysql-toolsUpgrade libmysql55client18-x86Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-develUpgrade mysql | Dec 18, 2015 | Jul 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub