Exposição de OpenSSL

Web server extensions
159
score de exposição
68.993
sites usam
0
em exploração
9
críticos
Análise Vexday

Com 152 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o OpenSSL apresenta um volume relevante de vulnerabilidades acumuladas, embora sua taxa de exploração ativa esteja abaixo da média geral do catálogo KEV — nenhuma de suas falhas consta atualmente no registro de vulnerabilidades exploradas pelo CISA. Ainda assim, o cenário exige atenção: o maior EPSS observado chega a 0,957, valor próximo ao limite máximo da escala, associado à CVE-2022-2068, o que indica altíssima probabilidade de exploração segundo os modelos preditivos. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), que pode resultar em condições de negação de serviço em implementações que dependem da biblioteca. As 8 CVEs de severidade crítica reforçam a necessidade de ciclos de atualização rigorosos em qualquer ambiente que utilize OpenSSL como componente de infraestrutura criptográfica.

CVEs

157 resultados
CVE-2022-3358Using a Custom Cipher with NID_undef may lead to NULL encryptionEPSS 3.0%CVE-2021-23839Incorrect SSLv2 rollback protectionEPSS 3.0%CVE-2024-4741HIGHUse After Free with SSL_free_buffersEPSS 2.9%CVE-2011-4121The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used foEPSS 2.5%CVE-2022-1473HIGHResource leakage when decoding certificates and keysEPSS 2.5%CVE-2024-12797MEDIUMRFC7250 handshakes with unauthenticated servers don't abort as expectedEPSS 2.4%CVE-2020-25644A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attackeEPSS 2.4%CVE-2023-6129MEDIUMPOLY1305 MAC implementation corrupts vector registers on PowerPCEPSS 2.3%CVE-2023-6237MEDIUMExcessive time spent checking invalid RSA public keysEPSS 2.3%CVE-2025-9232MEDIUMOut-of-bounds read in HTTP client no_proxy handlingEPSS 2.3%CVE-2025-9231MEDIUMTiming side-channel in SM2 algorithm on 64 bit ARMEPSS 2.2%CVE-2023-0401HIGHNULL dereference during PKCS7 data verificationEPSS 1.8%CVE-2023-0216HIGHInvalid pointer dereference in d2i_PKCS7 functionsEPSS 1.8%CVE-2023-0217HIGHNULL dereference validating DSA public keyEPSS 1.8%CVE-2025-9230HIGHOut-of-bounds read & write in RFC 3211 KEK UnwrapEPSS 1.7%CVE-2023-0466MEDIUMCertificate policy check not enabledEPSS 1.6%CVE-2023-0465MEDIUMInvalid certificate policies in leaf certificates are silently ignoredEPSS 1.6%CVE-2016-8517A cross site scripting vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.EPSS 1.5%CVE-2022-4203MEDIUMX.509 Name Constraints Read Buffer OverflowEPSS 1.5%CVE-2022-3996HIGHX.509 Policy Constraints Double LockingEPSS 1.2%