There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING.
When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade edk2-toolsUpgrade openssl-develUpgrade compat-openssl10Upgrade openssl-perlUpgrade edk2-aarch64Upgrade openssl-libsUpgrade edk2-ovmfUpgrade opensslUpgrade edk2-tools-docUpgrade compat-openssl11 | Mar 1, 2023 | Feb 8, 2023 |
| Alpine Linux | — | Upgrade openssl3Upgrade openssl1.1-compatUpgrade openssl | Aug 22, 2024 | Feb 8, 2023 |
| Amazon Linux Ami 2 | — | Upgrade openssl-libsUpgrade edk2-tools-pythonUpgrade openssl-debuginfoUpgrade openssl11-staticUpgrade openssl-snapsafe-staticUpgrade openssl-develUpgrade edk2-aarch64Upgrade edk2-ovmfUpgrade openssl-snapsafeUpgrade openssl11-libsUpgrade edk2-toolsUpgrade openssl-snapsafe-perlUpgrade openssl-snapsafe-develUpgrade openssl-snapsafe-debuginfoUpgrade opensslUpgrade openssl11-develUpgrade openssl11-debuginfoUpgrade edk2-tools-docUpgrade edk2-debuginfoUpgrade openssl11Upgrade openssl-snapsafe-libsUpgrade openssl-perlUpgrade openssl-static | Feb 9, 2023 | Feb 9, 2023 |
| Amazon_linux | — | Upgrade openssl | Feb 9, 2023 | Feb 7, 2023 |
| Amazon_linux_2023 | — | Upgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-debuginfo | Feb 17, 2025 | Feb 7, 2023 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | Apr 5, 2023 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | Apr 5, 2023 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | Apr 5, 2023 |
| Aruba Ecos | — | - AirWave Management Platform
- 8.3.0.1 and above (Release ETA - Mid June 2023)
- Aruba Analytics and Location Engine
- 2.2.0.4 and above
- Aruba Central On-Premises (COP)
- 2.5.7.0 and above (Release ETA - Early Aug 2023)
- Aruba ClearPass Policy Manager
- 6.11.3 and above
- 6.10.8 Hotfix 1 for Security Issues and above
- 6.9.13 Hotfix 1 for Security Issues and above
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.4.2 and above
- ArubaOS-CX Switches
- 10.11.1010 and above
- 10.10.1070 and above (Release ETA - Mid June 2023)
- 10.06.0240 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- ArubaOS 8.11.x.x: 8.11.1.0 and above
- ArubaOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- ArubaOS 8.6.x.x: 8.6.0.21 and above
- Aruba InstantOS / Aruba Access Points running ArubaOS 10
- ArubaOS 10.4.0.x: 10.4.0.1 and above
- Aruba InstantOS 8.11.x.x: 8.11.1.0 and above
- Aruba InstantOS 8.10.x.x: 8.10.0.7 and above (Release ETA - early June 2023)
- Aruba InstantOS 8.6.x.x: 8.6.0.21 and above
- Aruba EdgeConnect Enterprise
- ECOS 9.3.0.0 and above
- ECOS 9.2.4.0 and above
- ECOS 9.1.6.0 and above
- ECOS 9.0.9.0 and above
- Aruba EdgeConnect Enterprise Orchestrator (self-hosted, on prem or cloud IaaS)
- Self-hosted Orchestrators must have OpenSSL patched either by installing an RPM package or running yum update depending on the deployment model. Upgrading the Orchestrator application does not resolve these vulnerabilities.
- Customers will find further mitigation information with specific actions published at the following URL
https://www.arubanetworks.com/website/techdocs/sdwan-PDFs/docs/advisories/ec_resolution_openssl_cves_latest.pdf
- Aruba EdgeConnect Enterprise Orchestrator-as-a-Service (OaaS)
- Aruba EdgeConnect Enterprise Orchestrator Global Enterprise tenant OaaS instances
- Aruba EdgeConnect Enterprise Orchestrator-SP tenant OaaS instances
- Need to be upgraded to:
- Orchestrator 9.3.0 and above
- Orchestrator 9.2.4 and above
- Orchestrator 9.1.7 and above
Aruba does not evaluate or patch product versions that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Mar 17, 2025 | Apr 5, 2023 |
| Centos_linux | — | Upgrade opensslUpgrade openssl-staticUpgrade openssl-perlUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-devel | Mar 1, 2023 | Feb 8, 2023 |
| Debian | — | Upgrade openssl | Feb 9, 2023 | Feb 9, 2023 |
| Dell Poweredge Dsa2023134 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | May 23, 2023 |
| Dell Poweredge Dsa2023207 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | Aug 21, 2023 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| Dell Powerstore Dsa2024225 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 29, 2024 |
| Dell Powerstore Dsa2025086 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Feb 20, 2025 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 14, 2023 |
| Freebsd | — | Upgrade py310-cryptographyUpgrade python37Upgrade FreeBSDUpgrade python39Upgrade py39-cryptographyUpgrade opensslUpgrade py38-cryptographyUpgrade python311Upgrade openssl-quictlsUpgrade python38Upgrade py311-cryptographyUpgrade python310Upgrade openssl-develUpgrade py37-cryptography | Aug 31, 2023 | Aug 31, 2023 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Feb 5, 2024 | Feb 8, 2023 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 8, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade shim | May 18, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libsgx-urtsUpgrade libsgx-ae-leUpgrade libsgx-enclave-commonUpgrade libsgx-launchUpgrade libsgx-aesm-launch-pluginUpgrade sgx-aesm-service | Jul 5, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade openssl | Jun 9, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-devel | Apr 13, 2023 | Feb 8, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade shim | May 10, 2023 | Feb 8, 2023 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory38 | Jul 27, 2023 | Feb 8, 2023 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade openssl-libsUpgrade OVMFUpgrade openssl-develUpgrade compat-openssl11Upgrade edk2-tools-docUpgrade edk2-toolsUpgrade openssl-perlUpgrade edk2-aarch64Upgrade AAVMFUpgrade edk2-ovmfUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-staticUpgrade compat-openssl10 | Mar 2, 2023 | Feb 7, 2023 |
| Rapid7 Insightagent | — | Upgrade Rapid7 Insight Agent to version 4.0.6.14 | Mar 19, 2024 | Feb 8, 2023 |
| Redhat_linux | — | Upgrade compat-openssl11-debugsourceUpgrade opensslUpgrade edk2-tools-debuginfoUpgrade edk2-ovmfUpgrade openssl-libsUpgrade compat-openssl11Upgrade edk2-tools-docUpgrade openssl-debuginfoUpgrade compat-openssl10-debugsourceUpgrade edk2-aarch64Upgrade openssl-libs-debuginfoUpgrade compat-openssl10-debuginfoUpgrade compat-openssl11-debuginfoUpgrade edk2-toolsUpgrade compat-openssl10Upgrade edk2-debugsourceUpgrade openssl-perlNo solution existsUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-static | Mar 1, 2023 | Feb 8, 2023 |
| Rocky_linux | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade compat-openssl10-debugsourceUpgrade compat-openssl11-debugsourceUpgrade openssl-debugsourceUpgrade compat-openssl11Upgrade compat-openssl10Upgrade compat-openssl11-debuginfoUpgrade compat-openssl10-debuginfoUpgrade opensslUpgrade openssl-perlUpgrade openssl-libs-debuginfo | Mar 12, 2024 | Feb 8, 2023 |
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Apr 3, 2023 | Feb 9, 2023 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen6 NSv to version 6.5.4.4-44v-21-2079 or laterUpdate SonicWall SonicOS Gen6 (TZ, NSA) to version 6.5.4.12-101n or later | Jun 12, 2026 | Feb 9, 2023 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 8.2.11Upgrade Splunk Universal Forwarder to version 9.0.5Upgrade Splunk Universal Forwarder to version 8.1.14Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Enterprise to version 8.2.11Upgrade Splunk Enterprise to version 9.0.5 | Sep 30, 2025 | Feb 8, 2023 |
| Suse | — | Upgrade libopenssl1_0_0-steamUpgrade libopenssl1_1-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_1-docUpgrade libopenssl3-32bitUpgrade openssl-docUpgrade openssl-1_1-livepatchesUpgrade libopenssl1_1-hmac-32bitUpgrade openssl-1_0_0Upgrade libopenssl1_0_0-hmac-32bitUpgrade opensslUpgrade openssl1-docUpgrade libopenssl-develUpgrade libopenssl1_0_0Upgrade libopenssl1_1Upgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0-steam-32bitUpgrade libopenssl-3-devel-32bitUpgrade libopenssl1_1-hmacUpgrade openssl-3-docUpgrade libopenssl1_0_0-hmacUpgrade libopenssl-1_0_0-develUpgrade libopenssl10Upgrade libopenssl3Upgrade libopenssl1-develUpgrade openssl-1_0_0-cavsUpgrade openssl-1_0_0-docUpgrade libopenssl-3-develUpgrade openssl-3Upgrade openssl-1_1Upgrade libopenssl-1_1-develUpgrade openssl1 | Feb 8, 2023 | Feb 7, 2023 |
| Ubuntu | — | Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl3Upgrade libssl1.0.0Upgrade nodejsUpgrade libnode72Upgrade qemu-efi-aarch64Upgrade qemu-efi-loongarch64Upgrade libssl1.1Upgrade qemu-efi-riscv64Upgrade qemu-efiUpgrade ovmfUpgrade qemu-efi-armUpgrade libnode-devUpgrade ovmf-ia32 | Mar 14, 2023 | Feb 8, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 8, 2023 |
| Zimbra Collaboration | — | Upgrade Zimbra Collaboration to the latest version | Jan 20, 2025 | Feb 8, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub