Improper Authentication in OpenSSL - CVE-2023-2975
Published: July 15, 2023 / Updated: August 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the AES-SIV cipher implementation when authenticating empty data entries via the EVP_EncryptUpdate() and EVP_CipherUpdate() functions. A remote attacker can bypass authentication process and impact application's integrity.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Basesystem Module
openSUSE Leap
Junos OS Evolved
Ubuntu
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
Storage Virtualize
Dell Data Protection Central
Voice Gateway
Cisco Webex Meetings
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Service Interconnect
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Rational ClearQuest
IBM Rational ClearCase
Red Hat OpenStack
Cisco Jabber
VMware Horizon Client
Red Hat OpenShift Container Platform
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
libssl3 (Ubuntu package)
openssl-fips-provider (Red Hat package)
openssl (Red Hat package)
openssl
libopenssl-3-devel
libopenssl3-32bit
libopenssl3-32bit-debuginfo
openssl-3-doc
libopenssl-3-devel-32bit
libopenssl3
openssl-3-debuginfo
libopenssl3-64bit-debuginfo
libopenssl-3-devel-64bit
libopenssl3-debuginfo
libopenssl3-64bit
openssl-3
openssl-3-debugsource
dev-libs/openssl
SIMATIC MV500
Dell EMC VxRail Appliance
IBM App Connect Enterprise
How to mitigate CVE-2023-2975
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Voice Gateway - update to 1.0.8.12
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
OpenShift API for Data Protection (OADP) - update to 1.3.2
Service Interconnect - update to 1.5.4
Network Observability plugin for the Openshift Console - update to 1.6.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.10.5
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-394
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.12, 3.0.8-1ubuntu1.4, 3.0.10-1ubuntu2.1
openssl-fips-provider (Red Hat package) - update to 3.0.7-2.el9
openssl (Red Hat package) - update to 3.0.7-27.el9
openssl - update to 3.0.8-1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3 - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3 - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
dev-libs/openssl - update to 3.0.10
SIMATIC MV500 - update to 3.3.5
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.16.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
OpenShift Virtualization - update to 4.14.6
Red Hat OpenShift Container Platform - update to 4.17.0
App Connect Enterprise Certified Container - addressed in versions 5.0.12, 10.1.0
Red Hat Migration Toolkit for Applications - addressed in versions 6.2.3, 7.0.3
Dell EMC VxRail Appliance - update to 8.0.120
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.3, 10.15.3
Storage Virtualize - addressed in versions 8.7.0.3, 8.7.2.0
IBM Rational ClearQuest - addressed in versions 9.1.0.6, 10.0.5
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.0
Red Hat OpenStack - update to 17.1
Dell Data Protection Central - update to 19.11.0-2
External References
Related Security Bulletins
- Authentication bypass in OpenSSL AES-SIV cipher implementation
- SUSE update for openssl-3
- SUSE update for openssl-3
- Improper authentication in IBM App Connect Enterprise
- Ubuntu update for openssl
- Improper authentication in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Siemens SIMATIC MV500
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for OpenSSL
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Gentoo update for OpenSSL
- Improper authentication in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Rational ClearCase
- Red Hat Enterprise Linux 9 update for openssl and openssl-fips-provider
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.6
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.12
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 6.2
- Multiple vulnerabilities in Service Interconnect 1.5
- Junos OS Evolved update for OpenSSL
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in OpenShift Container Platform for Windows Containers 10.15
- Multiple vulnerabilities in OpenShift Container Platform for Windows Containers 8.1
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0