AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-0591

LOW · CVSS 2.6 EPSS 2.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-03-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-0591
Severity
LOW
CVSS
2.6
EPSS
2.73%
OpenSSL

Original NVD Description

The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.