CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.0 are vulnerable due to the use of HKDF without salt and a static info parameter in key normalization, which compromises the entropy of key derivation. This flaw allows attackers to exploit predictable key generation, significantly weakening cryptographic security and increasing the risk of multi-target attacks. Organizations using affected versions of OpenSSL should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)