NVD - CVE-2023-0464 (original) (raw)

CVE-2023-0464 Detail

Current Description

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.

View Analysis Description

Analysis Description

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.

Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.

CVSS 4.0 Severity and Vector Strings:

NIST CVSS score

NIST: NVD

N/A

NVD assessment not yet provided.

CVSS 3.x Severity and Vector Strings:

NIST CVSS score

NIST: NVD

Base Score: 7.5 HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

ADP: CISA-ADP

Base Score: 7.5 HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS 2.0 Severity and Vector Strings:

National Institute of Standards and Technology

NIST: NVD

Base Score: N/A

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545 CVE, OpenSSL Software Foundation Mailing List Patch
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e CVE, OpenSSL Software Foundation Broken Link
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b CVE, OpenSSL Software Foundation Mailing List Patch
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1 CVE, OpenSSL Software Foundation Mailing List Patch
https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html CVE, OpenSSL Software Foundation
https://security.gentoo.org/glsa/202402-08 CVE, OpenSSL Software Foundation
https://security.netapp.com/advisory/ntap-20230406-0006/ CVE
https://security.netapp.com/advisory/ntap-20240621-0006/ CVE, OpenSSL Software Foundation
https://www.couchbase.com/alerts/ CVE, OpenSSL Software Foundation
https://www.debian.org/security/2023/dsa-5417 CVE, OpenSSL Software Foundation
https://www.openssl.org/news/secadv/20230322.txt CVE, OpenSSL Software Foundation Vendor Advisory

Weakness Enumeration

CWE-ID CWE Name Source
CWE-295 Improper Certificate Validation cwe source acceptance level NIST CISA-ADP

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

11 change records found show changes

CVE Modified by CISA-ADP 6/17/2026 1:25:36 AM

Action Type Old Value New Value
Added SSVC {"timestamp":"2025-04-23T13:26:32.875761Z","id":"CVE-2023-0464","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}

CVE Modified by OpenSSL Software Foundation 6/17/2026 1:25:36 AM

Action Type Old Value New Value
Added Affected [{"vendor":"OpenSSL","product":"OpenSSL","defaultStatus":"unaffected","versions":[{"version":"3.1.0","lessThan":"3.1.1","versionType":"semver","status":"affected"},{"version":"3.0.0","lessThan":"3.0.9","versionType":"semver","status":"affected"},{"version":"1.1.1","lessThan":"1.1.1u","versionType":"custom","status":"affected"},{"version":"1.0.2","lessThan":"1.0.2zh","versionType":"custom","status":"affected"}]}]

CVE Modified by CISA-ADP 5/05/2025 12:15:26 PM

Action Type Old Value New Value
Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Added CWE CWE-295

CVE Modified by CVE 11/21/2024 2:37:13 AM

Action Type Old Value New Value
Added Reference https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545
Added Reference https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e
Added Reference https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b
Added Reference https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1
Added Reference https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html
Added Reference https://security.gentoo.org/glsa/202402-08
Added Reference https://security.netapp.com/advisory/ntap-20230406-0006/
Added Reference https://security.netapp.com/advisory/ntap-20240621-0006/
Added Reference https://www.couchbase.com/alerts/
Added Reference https://www.debian.org/security/2023/dsa-5417
Added Reference https://www.openssl.org/news/secadv/20230322.txt

CVE Modified by OpenSSL Software Foundation 6/21/2024 3:15:24 PM

Action Type Old Value New Value
Added Reference OpenSSL Software Foundation https://security.netapp.com/advisory/ntap-20240621-0006/ [No types assigned]

CVE Modified by OpenSSL Software Foundation 5/14/2024 7:59:24 AM

Action Type Old Value New Value

CVE Modified by OpenSSL Software Foundation 2/04/2024 4:15:09 AM

Action Type Old Value New Value
Added Reference OpenSSL Software Foundation https://security.gentoo.org/glsa/202402-08 [No types assigned]

CVE Modified by OpenSSL Software Foundation 11/09/2023 8:15:07 AM

Action Type Old Value New Value
Added Reference OpenSSL Software Foundation https://www.couchbase.com/alerts/ [No types assigned]

CVE Modified by OpenSSL Software Foundation 6/08/2023 3:15:09 PM

Action Type Old Value New Value
Added Reference https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html [No Types Assigned]

CVE Modified by OpenSSL Software Foundation 5/31/2023 8:15:09 PM

Action Type Old Value New Value
Changed Description A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
Added Reference https://www.debian.org/security/2023/dsa-5417 [No Types Assigned]

Initial Analysis by NIST 3/29/2023 3:37:35 PM

Action Type Old Value New Value
Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Added CWE NIST CWE-295
Added CPE Configuration OR *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.0.2 up to (excluding) 1.0.2zh *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.1.1 up to (excluding) 1.1.1u *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 3.0.0 up to (excluding) 3.0.9 *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 3.1.0 up to (excluding) 3.1.1
Changed Reference Type https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545 No Types Assigned https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545 Mailing List, Patch
Changed Reference Type https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e No Types Assigned https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e Broken Link
Changed Reference Type https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b No Types Assigned https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b Mailing List, Patch
Changed Reference Type https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1 No Types Assigned https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1 Mailing List, Patch
Changed Reference Type https://www.openssl.org/news/secadv/20230322.txt No Types Assigned https://www.openssl.org/news/secadv/20230322.txt Vendor Advisory

Quick Info

CVE Dictionary Entry:
CVE-2023-0464
NVD Published Date:
03/22/2023
NVD Last Modified:
06/17/2026
Source:
OpenSSL Software Foundation