Improper certificate validation in cryptography - CVE-2023-38325
Published: August 14, 2023
Vulnerability identifier: #VU79490
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38325
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation when handling SSH certificates that have critical options. A remote attacker can perform MitM attack.
Affected software
cryptography
IBM Observability with Instana
z/Transaction Processing Facility ( z/TPF)
IBM Process Mining
IBM Cloud Pak for Data System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle Communications Diameter Signaling Router
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
QRadar Suite
Fedora
python-yfinance
rust-asn1_derive
rust-asn1
python-cryptography
Storage Sentinel Anomaly Scan Engine
Storage Virtualize
Cloud Pak for Network Automation
Netezza Performance Server Replication Services
QRadar Deployment Intelligence App
Cinder Plug-in
IBM Cloud Pak for Watson AIOps
SOAR QRadar Plugin App
IBM Netezza for Cloud Pak for Data
IBM Qradar SIEM
IBM Observability with Instana
z/Transaction Processing Facility ( z/TPF)
IBM Process Mining
IBM Cloud Pak for Data System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle Communications Diameter Signaling Router
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
QRadar Suite
Fedora
python-yfinance
rust-asn1_derive
rust-asn1
python-cryptography
Storage Sentinel Anomaly Scan Engine
Storage Virtualize
Cloud Pak for Network Automation
Netezza Performance Server Replication Services
QRadar Deployment Intelligence App
Cinder Plug-in
IBM Cloud Pak for Watson AIOps
SOAR QRadar Plugin App
IBM Netezza for Cloud Pak for Data
IBM Qradar SIEM
How to mitigate CVE-2023-38325
Install updates from vendor's website.
cryptography - update to 41.0.2
QRadar Suite - update to 1.10.18.0
IBM Process Mining - update to 1.14.2
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
python-yfinance - update to 0.2.28-4.fc38
rust-asn1_derive - addressed in versions 0.15.5-1.fc39, 0.15.5-1.fc40
rust-asn1 - addressed in versions 0.15.5-2.fc39, 0.15.5-2.fc40
Storage Sentinel Anomaly Scan Engine - update to 1.1.6
Storage Virtualize - update to 2.1.0
Cloud Pak for Network Automation - update to 2.6.2
Netezza Performance Server Replication Services - update to 3.0.5.1
QRadar Deployment Intelligence App - update to 3.0.16
Cinder Plug-in - update to 3.9
IBM Cloud Pak for Watson AIOps - update to 4.2.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
SOAR QRadar Plugin App - update to 5.4.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM Spectrum Protect Plus - update to 10.1.15.2
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
python-cryptography - addressed in versions 41.0.3-1.fc39, 41.0.3-1.fc40
QRadar Suite - update to 1.10.18.0
IBM Process Mining - update to 1.14.2
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
python-yfinance - update to 0.2.28-4.fc38
rust-asn1_derive - addressed in versions 0.15.5-1.fc39, 0.15.5-1.fc40
rust-asn1 - addressed in versions 0.15.5-2.fc39, 0.15.5-2.fc40
Storage Sentinel Anomaly Scan Engine - update to 1.1.6
Storage Virtualize - update to 2.1.0
Cloud Pak for Network Automation - update to 2.6.2
Netezza Performance Server Replication Services - update to 3.0.5.1
QRadar Deployment Intelligence App - update to 3.0.16
Cinder Plug-in - update to 3.9
IBM Cloud Pak for Watson AIOps - update to 4.2.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
SOAR QRadar Plugin App - update to 5.4.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM Spectrum Protect Plus - update to 10.1.15.2
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
python-cryptography - addressed in versions 41.0.3-1.fc39, 41.0.3-1.fc40
External References
Related Security Bulletins
- MitM attack in cryptography package for Python
- Fedora 40 update for python-cryptography, rust-asn1, rust-asn1_derive
- Fedora 39 update for python-cryptography, rust-asn1, rust-asn1_derive
- Fedora 38 update for python-yfinance
- Improper certificate validation in z/Transaction Processing Facility
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Improper certificate validation in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Improper certificate validation in IBM Storage Virtualize
- Improper certificate validation in IBM Process Mining
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for Python Cryptographic Authority
- Improper certificate validation in IBM Cinder plug-in
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- IBM Cloud Pak for Data System 2.0 update for cryptography package
- Multiple vulnerabilities in IBM Netezza Performance Server Replication Services