vulnerability

FreeBSD: VID-a64761a1-e895-11ef-873e-8447094a420f (CVE-2024-12797): OpenSSL -- Man-in-the-Middle vulnerability

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Feb 11, 2025
Added
Feb 12, 2025
Modified
Dec 10, 2025

Description

The OpenSSL project reports: RFC7250 handshakes with unauthenticated servers don't abort as expected (High). Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set.

Solutions

freebsd-upgrade-package-openssl32freebsd-upgrade-package-openssl33freebsd-upgrade-package-openssl34
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.