Rewterz
CVE-2024-7261 – Zyxel Vulnerability
September 5, 2024
Rewterz
CVE-2024-44400 – D-Link DI-8400 Vulnerability
September 5, 2024

CVE-2024-6119 – OpenSSL Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-6119

OpenSSL is vulnerable to a denial of service, caused by an error when performing certificate name checks (e.g., TLS clients checking server certificates). By sending a specially crafted request, a remote attacker could exploit this vulnerability to read an invalid memory address resulting in abnormal termination of the application process.

Impact

  • Denial of Service

Indicators of Compromise

CVE

  • CVE-2024-6119

Affected Vendors

OpenSSL

Affected Products

  • OpenSSL - 3.3.0
  • OpenSSL - 3.2.0
  • OpenSSL - 3.1.0
  • OpenSSL - 3.0.0

Remediation

Refer to OpenSSL Security Advisory for patch, upgrade or suggested workaround information.

OpenSSL Security Advisory