CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
AI Score
Confidence
High
A vulnerability in the OpenSSL library is related to reading the wrong address in memory when comparing subject names
otherName
of an X.509 certificate. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of service.
remotely to cause a denial of service
A vulnerability in the SSL_select_next_proto function of the OpenSSL TLS and SSL protocols toolkit is related to the
information disclosure. Exploitation of the vulnerability allows an attacker acting remotely to gain
access to sensitive data and also cause a denial of service