CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.0 are vulnerable due to a missing ownership verification in the revoke_key method, enabling authenticated clients to revoke any other client's key by presenting a valid ML-DSA signature. This flaw allows attackers to disrupt services by invalidating keys arbitrarily, posing a significant risk to the integrity of cryptographic operations. Organizations using affected OpenSSL versions should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
Related CVEs
Other vulnerabilities affecting the same vendor(s)