Unknown
CVE-2020-1967
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-1967
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the “signature_algorithms_cert” TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- broadcom,
- debian,
- fedoraproject,
- freebsd,
- jdedwards,
- netapp,
- openssl,
- opensuse,
- oracle,
- tenable
Products
- active iq unified manager,
- application server 12.1.3,
- debian linux 10.0,
- debian linux 9.0,
- e-series performance analyzer -,
- enterprise manager base platform 13.4.0.0,
- enterprise manager for storage management 13.3.0.0,
- enterprise manager for storage management 13.4.0.0,
- enterprise manager ops center 12.4.0,
- enterpriseone,
- fabric operating system -,
- fedora 30,
- fedora 31,
- fedora 32,
- freebsd 12.1,
- http server 12.2.1.4.0,
- jd edwards world security a9.4,
- leap 15.1,
- leap 15.2,
- log correlation engine,
- mysql,
- mysql connectors,
- mysql enterprise monitor,
- mysql workbench,
- oncommand insight -,
- oncommand workflow automation -,
- openssl,
- peoplesoft enterprise peopletools 8.56,
- peoplesoft enterprise peopletools 8.57,
- peoplesoft enterprise peopletools 8.58,
- peoplesoft enterprise peopletools 8.59,
- smi-s provider -,
- snapcenter -,
- steelstore cloud integrated storage -
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: