High level #vulnerability
#CVE_2024_12797 in #OpenSSL:
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don’t abort as expected when the SSL_VERIFY_PEER verification mode is set.
Impact summary: TLS and DTLS connections using raw public keys may be vulnerable to man-in-middle attacks when server authentication failure is not detected by clients.
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2024-12797
#infosec #cybersecurity #infosecurity
You must log in or register to comment.