CVE-2024-53846

EUVD-2024-52172
OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27.0, resulting in a server or client verifying the peer when incorrect extended key usage is presented (i.e., a server will verify a client if they have server auth ext key usage and vice versa).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.75%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
erlangotp
𝑥
≤ 25.3.2.8
ADP
Debian logo
Debian Releases
Debian Product
Codename
erlang
bookworm
1:25.2.3+dfsg-1+deb12u4
fixed
bookworm (security)
1:25.2.3+dfsg-1+deb12u1
fixed
bullseye
1:23.2.6+dfsg-1+deb11u1
fixed
bullseye (security)
1:23.2.6+dfsg-1+deb11u4
fixed
forky
1:29.0.3+dfsg-1
fixed
sid
1:29.0.3+dfsg-1
fixed
trixie
1:27.3.4.1+dfsg-1+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
erlang
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 1:25.3.2.8+dfsg-1ubuntu4.6
released
plucky
not-affected
questing
not-affected
trusty
not-affected
xenial
not-affected
Azure Linux logo
Azure Linux Releases
Azure Package
Release
erlang
Azure Linux 3.0
0:26.2.5.6-1.azl3
fixed