CVE-2009-0051
ZXID <0.29 - Certificate Validation Bypass
Title source: llmDescription
ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scores
EPSS
0.0009
EPSS Percentile
25.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (27)
zxid/zxid
< 0.29
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
zxid/zxid
... and 12 more
Timeline
Published
Jan 07, 2009
Tracked Since
Feb 18, 2026