PT-2024-29681 · Openssl+2 · Openssl+2
Published
2024-08-25
·
Updated
2026-01-24
·
CVE-2024-41996
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.x through 1.1.1
OpenSSL versions 3.x through 3.0.5
OpenSSL versions prior to 17.0.5
Description
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.
Recommendations
Upgrade to OpenSSL 1.1.1 or 3.0.5 to mitigate risks.
If you're using versions below 17.0.5, upgrade to 17.0.5 to mitigate risks.
As a temporary workaround, consider restricting the use of the Diffie-Hellman Key Agreement Protocol until a patch is available.
Patch systems and monitor resource usage to prevent system performance degradation.
Fix
Resource Exhaustion
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Red Os
Suse