Vulnerability record · CVE-2015-1793 · published 9 July 2015
CVE-2015-1793: OpenSSL X.509 Basic Constraints flaw allows CA role spoofing
Oracle · Supply Chain Products Suite
OpenSSL 1.0.1n, 1.0.1o, 1.0.2b and 1.0.2c mishandle X.509 Basic Constraints cA values while identifying alternative certificate chains in X509_verify_cert. A valid leaf certificate can therefore be used to spoof a Certification Authority role and trigger unintended certificate verifications. This undermines the trust decisions applications make when validating TLS and other X.509-based connections.
Description
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Automated analysis
high priorityThe flaw allows certificate trust bypass remotely without authentication, and although CVSS rates it medium, the very high EPSS percentile and broad downstream product exposure raise urgency.
What it is
OpenSSL 1.0.1n, 1.0.1o, 1.0.2b and 1.0.2c mishandle X.509 Basic Constraints cA values while identifying alternative certificate chains in X509_verify_cert. A valid leaf certificate can therefore be used to spoof a Certification Authority role and trigger unintended certificate verifications. This undermines the trust decisions applications make when validating TLS and other X.509-based connections.
Impact
An attacker can get a certificate accepted as if it were issued by a trusted CA, enabling impersonation of servers or other certificate-based identities. The CVSS 3.0 vector shows limited confidentiality and integrity impact, not full system compromise.
Attack surface
Reachable remotely over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The attacker only needs to present a crafted but valid leaf certificate to a vulnerable OpenSSL-based verifier.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high (0.62394, 99.1st percentile), indicating elevated likelihood of exploitation activity. References are vendor advisories and patches rather than public exploit tags.
What to do
- Upgrade OpenSSL to a version after 1.0.1o/1.0.2c that contains the fix, or apply the vendor patch referenced in the OpenSSL security advisory.
- Patch or upgrade downstream products that bundle affected OpenSSL versions, including Oracle, Juniper, Cisco, HPE, Huawei and NetBSD components listed in the references.
- Inventory and scan for embedded OpenSSL 1.0.1n, 1.0.1o, 1.0.2b and 1.0.2c in appliances and third-party software that may not be covered by normal OS patching.
- Where immediate patching is not possible, restrict or monitor certificate validation paths that rely on alternative chain building.
Detection
- Monitor TLS and certificate validation logs for unexpected chain-building failures or successes involving leaf certificates presented as CAs.
- Track OpenSSL version strings across hosts and services to find systems still running 1.0.1n, 1.0.1o, 1.0.2b or 1.0.2c.
- Alert on certificates with Basic Constraints cA values that do not match their role in the presented chain.
- Review vendor advisories and patch status for the listed Oracle, Juniper, Cisco, HPE, Huawei and NetBSD products.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1793 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1793), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.