CVE-2023-3446 describes a Denial of Service vulnerability in OpenSSL versions 3.0 and 3.1, affecting applications that use DH_check(), DH_check_ex(), or EVP_PKEY_param_check() to validate Diffie-Hellman (DH) keys or parameters. An attacker can provide excessively long DH parameters, causing significant delays during validation and potentially leading to a DoS. Rated as MEDIUM severity (CVSS 5.3), this vulnerability has a network attack vector with low complexity and no user interaction required, resulting in a low impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2:-:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.1:-:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:3.0.0:-:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:3.1.0:-:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:3.1.1:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-3446
Nov 12, 2024AS-2023-014: OpenSSL
Jul 17, 2024November 2023 Third Party Package updates in Splunk Enterprise
Nov 16, 2023November 2023 Third-Party Package Updates in Splunk Cloud Platform
Nov 16, 2023November 2023 Splunk Universal Forwarder Third-Party Updates
Nov 16, 2023openssl: Excessive time spent checking DH keys and parameters
Jul 19, 2023Excessive time spent checking DH keys and parameters
Jul 11, 2023