CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.0 are vulnerable due to an insecure default configuration that erroneously trusts the entire RFC 1918 private address space in the IntegrityProxyConfig trusted_proxies. This flaw allows attackers on private networks to forge client certificate headers, potentially bypassing mTLS authentication if ProxyAuth validation is not properly enforced. Organizations using affected versions of OpenSSL should prioritize updating to mitigate the risk of unauthorized access and ensure robust authentication mechanisms.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
Related CVEs
Other vulnerabilities affecting the same vendor(s)