#VU74149 Security features bypass in OpenSSL - CVE-2023-0466
Published: March 28, 2023 / Updated: October 11, 2023
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an error within the X509_VERIFY_PARAM_add0_policy() function, which does not perform the certificate policy check despite being implicitly enabled. A remote attacker can bypass expected security restrictions and perform MitM attack.