Improper certificate validation in cryptography - CVE-2023-38325

 

Improper certificate validation in cryptography - CVE-2023-38325

Published: August 14, 2023


Vulnerability identifier: #VU79490
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38325
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper certificate validation when handling SSH certificates that have critical options. A remote attacker can perform MitM attack.


Affected software

cryptography
IBM Observability with Instana
z/Transaction Processing Facility ( z/TPF)
IBM Process Mining
IBM Cloud Pak for Data System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle Communications Diameter Signaling Router
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
QRadar Suite
Fedora
python-yfinance
rust-asn1_derive
rust-asn1
python-cryptography
Storage Sentinel Anomaly Scan Engine
Storage Virtualize
Cloud Pak for Network Automation
Netezza Performance Server Replication Services
QRadar Deployment Intelligence App
Cinder Plug-in
IBM Cloud Pak for Watson AIOps
SOAR QRadar Plugin App
IBM Netezza for Cloud Pak for Data
IBM Qradar SIEM

How to mitigate CVE-2023-38325

Install updates from vendor's website.

cryptography - update to 41.0.2
QRadar Suite - update to 1.10.18.0
IBM Process Mining - update to 1.14.2
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
python-yfinance - update to 0.2.28-4.fc38
rust-asn1_derive - addressed in versions 0.15.5-1.fc39, 0.15.5-1.fc40
rust-asn1 - addressed in versions 0.15.5-2.fc39, 0.15.5-2.fc40
Storage Sentinel Anomaly Scan Engine - update to 1.1.6
Storage Virtualize - update to 2.1.0
Cloud Pak for Network Automation - update to 2.6.2
Netezza Performance Server Replication Services - update to 3.0.5.1
QRadar Deployment Intelligence App - update to 3.0.16
Cinder Plug-in - update to 3.9
IBM Cloud Pak for Watson AIOps - update to 4.2.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
SOAR QRadar Plugin App - update to 5.4.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM Spectrum Protect Plus - update to 10.1.15.2
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
python-cryptography - addressed in versions 41.0.3-1.fc39, 41.0.3-1.fc40

External References

Related Security Bulletins