Input validation error in OpenSSL - CVE-2023-4807

 

Input validation error in OpenSSL - CVE-2023-4807

Published: September 8, 2023 / Updated: July 3, 2024


Vulnerability identifier: #VU80565
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4807
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the POLY1305 MAC (message authentication code) implementation. A remote attacker can send specially crafted input to the application and corrupt MM registers on Windows 64 platform, resulting in a denial of service condition.


Affected software

OpenSSL
MELSOFT MaiLab SW1DND-MAILAB-M
MELSOFT MaiLab SW1DND-MAILABPR-M
Telemetry Dashboard
Liquidware
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
DB2 Query Management Facility
Citrix Workspace App
Webex App VDI
Secured Component Verification (SCV)
IBM Planning Analytics Workspace
Netezza Performance Server Replication Services
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Ceph
IBM Semeru Runtimes
IBM MQ Appliance
Host On-Demand
QRadar Suite
IBM Cloud Pak for Data System
IBM Rational Build Forge
Tenable Nessus
NetWorker
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM Cloud Transformation Advisor
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
IBM Spectrum Control
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Workload Scheduler
IBM QRadar WinCollect Agent
PowerProtect Data Manager
Juniper Cloud Native Router
IBM Cloud Pak for Multicloud Management
VMware Horizon Client
IBM DataPower Gateway
PeopleSoft Enterprise PeopleTools
Nessus Agent
TeleControl Server Basic
IBM Qradar SIEM
Hyper Historian
IceWall Gen11 certd module for Windows
IBM App Connect Enterprise
Cisco Jabber
Junos OS Evolved
Cisco Webex Meetings
Dell G15 5511
Alienware m15 R6
XPS 8960
Junos cRPD
IBM MaaS360 VPN Module
MobileHMI
ICONICS Suite
GENESIS64
Energy AnalytiX

How to mitigate CVE-2023-4807

Install update from vendor's website.

OpenSSL - update to 1.1.1w
MELSOFT MaiLab SW1DND-MAILAB-M - update to 1.06G
MELSOFT MaiLab SW1DND-MAILABPR-M - update to 1.06G
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.25
Nessus Agent - update to 10.4.3
Tenable Nessus - addressed in versions 10.5.6, 10.6.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.11.0.6, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
XPS 8960 - update to 2.3.0
Netezza Performance Server Replication Services - update to 3.0.5.1
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
IBM MaaS360 VPN Module - update to 3.000.400
TeleControl Server Basic - update to 3.1.2
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
EasyApache - update to 4 2023-9-20
IBM Spectrum Control - update to 5.4.11
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.1.0.2
Storage Ceph - update to 7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM Semeru Runtimes - addressed in versions 8.0.392.0, 11.0.21.0, 17.0.9.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11, 9.0.2
IBM Maximo Application Suite - addressed in versions 8.10.10, 8.11.7
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
IBM Rational ClearQuest - addressed in versions 9.1.0.6, 10.0.5
IBM MQ Appliance - addressed in versions 9.3.0.15, 9.3.4.1
IBM Workload Scheduler - addressed in versions 9.5.0.7, 10.1.0.4, 10.2.1
IBM DataPower Gateway - addressed in versions 10.0.1.16, 10.5.0.8, 10.5.3
IBM QRadar WinCollect Agent - update to 10.1.9
MobileHMI - update to 10.97.2
ICONICS Suite - update to 10.97.2
GENESIS64 - update to 10.97.2
Energy AnalytiX - update to 10.97.2
Hyper Historian - update to 10.97.2
Host On-Demand - update to 15.0.2
PowerProtect Data Manager - update to 19.19.0-15
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1

External References

Related Security Bulletins