Описание
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
EPSS
Процентиль: 13%
0.00228
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-347
Связанные уязвимости
CVSS3: 9.8
github
около 1 месяца назад
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
EPSS
Процентиль: 13%
0.00228
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-347