CVE-2024-53846

MEDIUM

Erlang/OTP 25.3.2.8-25.3.2.16, 26.2-26.2.5.6, 27.0-27.1.3 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27.0, resulting in a server or client verifying the peer when incorrect extended key usage is presented (i.e., a server will verify a client if they have server auth ext key usage and vice versa).

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (3)
erlang/otp >= 25.3.2.8, <= 25.3.2.16
erlang/otp >= 26.2, <= 26.2.5.6
erlang/otp >= 27.0, <= 27.1.3
Published Dec 05, 2024
Tracked Since Feb 18, 2026