#VU78265 Improper Authentication in OpenSSL - CVE-2023-2975
Published: July 15, 2023 / Updated: August 2, 2023
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the AES-SIV cipher implementation when authenticating empty data entries via the EVP_EncryptUpdate() and EVP_CipherUpdate() functions. A remote attacker can bypass authentication process and impact application's integrity.