CVE-2015-1793
6.5
MEDIUM
CVSS 3.1
EPSS 76.4%
Description
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
How to fix CVE-2015-1793
To remediate CVE-2015-1793, upgrade the affected package to a fixed version below.
- —upgrade to 1.0.2d-1 or later
Is CVE-2015-1793 being exploited?
Likely — EPSS is 76.4%, placing CVE-2015-1793 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1.0.2d-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |