CyberRota Analysis
AI-GeneratedA vulnerability in OpenSSL allows an unverified attacker Certificate Authority (CA) to be permanently planted in the shared CertManager, which bypasses certificate validation across various consumers, including native TLS and OCSP. This issue affects wolfSSL versions 5.8.4 through 5.9.2 when built with specific macros or configurations that utilize the X509_verify_cert function. Organizations using these versions of wolfSSL should prioritize remediation to mitigate the risk of unauthorized access and potential man-in-the-middle attacks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSL_EXTRA && !NO_CERTS && !WOLFCRYPT_ONLY) defined or built with --enable-opensslextra and the application is specifically making calls to the X509_verify_cert function.
Related CVEs
Other vulnerabilities affecting the same vendor(s)