CVE-2024-53846
MEDIUMErlang/OTP 25.3.2.8-25.3.2.16, 26.2-26.2.5.6, 27.0-27.1.3 - Improper Certificate Validation
Title source: llmDescription
OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27.0, resulting in a server or client verifying the peer when incorrect extended key usage is presented (i.e., a server will verify a client if they have server auth ext key usage and vice versa).
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://github.com/erlang/otp/security/advisories/GHSA-qw6r-qh9v-638v
Scores
CVSS v3
5.5
EPSS
0.0025
EPSS Percentile
15.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (3)
erlang/otp
>= 25.3.2.8, <= 25.3.2.16
erlang/otp
>= 26.2, <= 26.2.5.6
erlang/otp
>= 27.0, <= 27.1.3
Published
Dec 05, 2024
Tracked Since
Feb 18, 2026