Improper Certificate Validation in Botan - CVE-2022-43705

 

Improper Certificate Validation in Botan - CVE-2022-43705

Published: November 16, 2022 / Updated: April 8, 2026


Vulnerability identifier: #VU125380
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-43705
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spoof certificate revocation status and bypass revocation checks.

The vulnerability exists due to improper certificate validation in OCSP response verification when processing embedded OCSP responder certificates. A remote privileged user can spoof a crafted OCSP response to spoof certificate revocation status and bypass revocation checks.

Only deployments that rely on OCSP for certificate revocation checks are affected. The issue can be exploited in scenarios such as OCSP stapling.


Affected software

Botan
Fedora
botan2

How to mitigate CVE-2022-43705

Install security update from vendor's website.

Botan - addressed in versions 2.19.3, 3.0.0
botan2 - update to 2.19.3-1.el9

External References

Related Security Bulletins