Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10550

Опубликовано: 13 мар. 2026
Источник: fstec
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv связана с выбором менее безопасного алгоритма в процессе согласования. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить атаку типа «человек посередине»

Вендор

ООО «Ред Софт»
Red Hat Inc.
Сообщество свободного программного обеспечения
Siemens AG
OpenSSL Software Foundation

Наименование ПО

РЕД ОС
Red Hat Enterprise Linux
Debian GNU/Linux
Red Hat Hardened Images
SIMATIC CN 4100
relenv
OpenSSL
Red Hat JBoss Web Server
Red Hat JBoss Core Services

Версия ПО

7.3 (РЕД ОС)
9 (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
- (Red Hat Hardened Images)
до 5.0 (SIMATIC CN 4100)
до 0.22.14 (relenv)
до 3.6.2 (OpenSSL)
до 3.5.6 (OpenSSL)
7.0.0 (Red Hat JBoss Web Server)
6.2.4 (Red Hat JBoss Web Server)
2.4.62.SP4 (Red Hat JBoss Core Services)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО программно-аппаратного средства АСУ ТП
Программное средство защиты
Сетевое средство
Микропрограммный код аппаратных компонентов компьютера

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
Red Hat Inc. Red Hat Enterprise Linux 9
Сообщество свободного программного обеспечения Debian GNU/Linux 13
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,4)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/advisories/GHSA-wj64-gh9j-xm82
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-2673
Для OpenSSL:
https://openssl-library.org/news/secadv/20260313.txt
Для Siemens AG:
https://cert-portal.siemens.com/productcert/html/ssa-032379.html

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 35%
0.00435
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
redos
20 дней назад

Уязвимость python-relenv

CVSS3: 6.5
ubuntu
5 месяцев назад

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even wh...

CVSS3: 6.5
redhat
5 месяцев назад

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even wh...

CVSS3: 6.5
nvd
5 месяцев назад

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even whe

CVSS3: 5.3
msrc
5 месяцев назад

OpenSSL TLS 1.3 server may choose unexpected key agreement group

EPSS

Процентиль: 35%
0.00435
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2