Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-5678

22
FAUCET Score

CVE-2023-5678 is a Denial of Service vulnerability affecting OpenSSL versions when generating or checking excessively long X9.42 DH keys or parameters. Specifically, functions like DH_generate_key() and DH_check_pub_key() can experience significant delays if supplied with untrusted, large parameters. The vulnerability has a CVSS score of 5.3 MEDIUM, indicating a network-based attack with low complexity, requiring no user interaction, and resulting in low availability impact. The OpenSSL SSL/TLS implementation and FIPS providers are not affected. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing. However, there is some community discussion and media coverage, suggesting awareness of the issue.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.0.2zjCPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.1, < 1.1.1xCPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.13CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.1.0, < 3.1.5CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.46%
Probability of exploitation in next 30 days
EPSS Percentile
90.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0446 is in the 87th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (63)

denopatch availablevia llm_extracted
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: cbl2 edk2 20230301gitf80f052277c8-38 on CBL Mariner 2.0Fixed in: 20230301gitf80f052277c8-38
microsoftpatch availablevia msrc
Product: azl3 edk2 20230301gitf80f052277c8-38 on Azure Linux 3.0Fixed in: 20230301gitf80f052277c8-38
microsoftpatch availablevia msrc
Product: cbl2 hvloader 1.0.1-11 on CBL Mariner 2.0Fixed in: 1.0.1-3
microsoftpatch availablevia msrc
Product: azl3 openssl 3.1.4-9 on Azure Linux 3.0Fixed in: 3.3.0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.0.1-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.0.1-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: 17859-17084Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: 20273-17084Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: 18370-17084Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: 17716-17084Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: 20276-17086Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: 19740-17084Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: 19801-17086Fixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: 19807-17084Fixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: 16977-16823Fixed in: -
microsoftpatch availablevia msrc
Product: 16982-17084Fixed in: -
microsoftpatch availablevia msrc
Product: 17374-16823Fixed in: 1.0.1-9
microsoftpatch availablevia msrc
Product: 18093-16823Fixed in: 1.1.1k-28
microsoftpatch availablevia msrc
Product: 18114-17084Fixed in: 1.1.1k-28
microsoftpatch availablevia msrc
Product: 18113-16823Fixed in: 20230301gitf80f052277c8-38
microsoftpatch availablevia msrc
Product: 18115-17084Fixed in: 20230301gitf80f052277c8-38
microsoftpatch availablevia msrc
Product: 19678-17086Fixed in: 1.0.1-3
microsoftpatch availablevia msrc
Product: 19786-17084Fixed in: 3.3.0-1
microsoftpatch availablevia msrc
Product: azl3 edk2 20230301gitf80f052277c8-37 on Azure Linux 3.0Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: azl3 kata-containers-cc 3.2.0.azl0-3 on Azure Linux 3.0Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: azl3 kata-containers 3.2.0.azl0-2 on Azure Linux 3.0Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: azl3 kata-containers 3.2.0.azl1-1 on Azure Linux 3.0Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: cbl2 kata-containers 3.2.0.azl0-2 on CBL Mariner 2.0Fixed in: 3.2.0.azl1-1
microsoftpatch availablevia msrc
Product: azl3 nodejs 20.10.0-2 on Azure Linux 3.0Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: cbl2 cloud-hypervisor-cvm 38.0.72-1 on CBL Mariner 2.0Fixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: azl3 cloud-hypervisor-cvm 38.0.72-2 on Azure Linux 3.0Fixed in: 38.0.72.2-1
microsoftpatch availablevia msrc
Product: cbl2 cloud-hypervisor-cvm 38.0.72.2-1 on CBL Mariner 2.0Fixed in: -
microsoftpatch availablevia msrc
Product: azl3 cloud-hypervisor-cvm 38.0.72.2-1 on Azure Linux 3.0Fixed in: -
microsoftpatch availablevia msrc
Product: cbl2 hvloader 1.0.1-9 on CBL Mariner 2.0Fixed in: 1.0.1-9
microsoftpatch availablevia msrc
Product: cbl2 openssl 1.1.1k-28 on CBL Mariner 2.0Fixed in: 1.1.1k-28
microsoftpatch availablevia msrc
Product: azl3 openssl 1.1.1k-28 on Azure Linux 3.0Fixed in: 1.1.1k-28
redhatpatch availablevia redhat_api
Product: JWS 5.7.8Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1k-12.el8_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: openssl-1:1.1.1k-12.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: openssl-1:1.1.1k-12.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: openssl-1:3.0.7-27.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.7 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.31-17.redhat_17.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.7 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.31-17.redhat_17.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.7 on RHEL 9Fixed in: jws5-tomcat-native-0:1.2.31-17.redhat_17.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: jbcs-httpd24-openssl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1k-17.el7jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-1:1.1.1k-17.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JWS 6.0.1Fixed in: openssl
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: compat-openssl10
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: compat-openssl11

Vendor Advisories (5)

microsoft2024-Sep/CVE-2023-5678

CVE-2023-5678

Sep 10, 2024
denollm-deno-b67a3af2ce0be075CRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
kerasllm-keras-7d8c31fee70361dcCRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
microsoft2023-Nov/CVE-2023-5678Moderate

Excessive time spent in DH check / generation with large Q parameter value

Nov 14, 2023
redhatCVE-2023-5678Low

openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow

Oct 24, 2023

References

cert-portal.siemens.com / productcert/html/ssa-093430.html
cert-portal.siemens.com / productcert/html/ssa-128433.html
cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-277137.html
cert-portal.siemens.com / productcert/html/ssa-331112.html
cert-portal.siemens.com / productcert/html/ssa-341067.html
cert-portal.siemens.com / productcert/html/ssa-398330.html
cert-portal.siemens.com / productcert/html/ssa-556635.html
cert-portal.siemens.com / productcert/html/ssa-613116.html
cert-portal.siemens.com / productcert/html/ssa-769027.html
cert-portal.siemens.com / productcert/html/ssa-794697.html
cert-portal.siemens.com / productcert/html/ssa-915275.html
lists.debian.org / debian-lts-announce/2024/10/msg00033.html
lists.debian.org / debian-lts-announce/2024/11/msg00000.html
security.netapp.com / advisory/ntap-20231130-0010
openwall.com / lists/oss-security/2024/03/11/1
git.openssl.org / gitweb
Broken Link
git.openssl.org / gitweb
Broken Link
git.openssl.org / gitweb
Mailing ListPatch
git.openssl.org / gitweb
Mailing ListPatch
openssl.org / news/secadv/20231106.txt
Vendor Advisory