CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.9 are vulnerable to an authentication bypass in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. This flaw enables unauthorized modification of file headers, potentially compromising data recovery mechanisms intentionally established by the file owner. Organizations utilizing affected versions of OpenSSL should prioritize updating to mitigate the risk of data loss and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
Related CVEs
Other vulnerabilities affecting the same vendor(s)