CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.9 are vulnerable due to inadequate validation of the encryption status for embedded post-quantum private keys in file metadata. This flaw allows attackers to create files containing unencrypted PQC keys that can be decrypted with any password, enabling them to bypass authentication and generate attacker-controlled plaintext while compromising data integrity. Organizations utilizing affected versions of OpenSSL, especially those handling sensitive cryptographic operations, should prioritize patching this vulnerability to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification.
Related CVEs
Other vulnerabilities affecting the same vendor(s)