CVE-2020-1967 is a high-severity Denial of Service (DoS) vulnerability affecting OpenSSL versions 1.1.1d through 1.1.1f, specifically impacting server or client applications that call SSL_check_chain() during or after a TLS 1.3 handshake. This flaw, a NULL pointer dereference (CWE-476), occurs when an invalid or unrecognized signature algorithm is received from a peer, leading to application crashes. With a CVSS score of 7.5 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in a complete loss of availability. Although no active exploitation has been confirmed and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, the vulnerability has garnered significant community discussion and media coverage, including reports of a Proof-of-Concept (PoC) exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.1d, <= 1.1.1fCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:12.1:-:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.