← Vulnerability feed

Vulnerability record · CVE-2023-0286 · published 8 February 2023

CVE-2023-0286: OpenSSL X.400 GeneralName type confusion in X.509 CRL checking

OOpenssl · Openssl

OpenSSL parses X.400 addresses in an X.509 GeneralName as ASN1_STRING, but the public GENERAL_NAME structure declares the x400Address field as ASN1_TYPE, and GENERAL_NAME_cmp later interprets it as ASN1_TYPE. When CRL checking is enabled (X509_V_FLAG_CRL_CHECK), this type confusion lets an attacker pass arbitrary pointers to memcmp, causing out-of-bounds reads or a crash. It matters because certificate and CRL inputs need not be validly signed, so untrusted data can reach the vulnerable comparison.

7.4 CVSS 3.1 High EPSS 60% · top 0.9% CWE-843 · Type confusion
7.4CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
15References
17 Jun 2026Last modified by NVD

Description

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.4 high severity with high confidentiality and availability impact, and a very high EPSS percentile, though exploitation requires CRL checking to be enabled and specific input control.

What it is

OpenSSL parses X.400 addresses in an X.509 GeneralName as ASN1_STRING, but the public GENERAL_NAME structure declares the x400Address field as ASN1_TYPE, and GENERAL_NAME_cmp later interprets it as ASN1_TYPE. When CRL checking is enabled (X509_V_FLAG_CRL_CHECK), this type confusion lets an attacker pass arbitrary pointers to memcmp, causing out-of-bounds reads or a crash. It matters because certificate and CRL inputs need not be validly signed, so untrusted data can reach the vulnerable comparison.

Impact

An attacker can read memory contents or trigger a denial of service in applications that perform CRL checking. No code execution is described in the record.

Attack surface

Reached remotely over the network through X.509 certificate chain and CRL processing when the application sets X509_V_FLAG_CRL_CHECK; no authentication or user interaction is required per the CVSS vector. The attack generally requires the attacker to supply both the certificate chain and the CRL, or the other input must already contain an X.400 address as a CRL distribution point, which the description calls uncommon.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS 30-day probability is 0.59501 (99.08th percentile), indicating high predicted exploitation likelihood. References are patch and vendor advisory links only, with no public exploit tag.

What to do

  • Upgrade OpenSSL to a release containing the fixes referenced in the OpenSSL security advisory 20230207 and the linked git commits.
  • Patch or update dependent products listed as affected (Stormshield management center and network security) per vendor guidance.
  • Where immediate patching is not possible, avoid enabling X509_V_FLAG_CRL_CHECK or restrict CRL retrieval to trusted, controlled sources.
  • Do not rely on signature validity of supplied certificate chains or CRLs as a control, since the flaw is reachable with unsigned inputs.

Detection

  • Monitor application and service logs for crashes or abnormal terminations during TLS or certificate validation with CRL checking enabled.
  • Track OpenSSL library versions across hosts and flag systems still running unpatched builds.
  • Watch for unexpected or attacker-supplied CRL distribution point URLs containing X.400 addresses in certificate processing paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-0286 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-31789Openssl out-of-bounds write vulnerabilityIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact…EPSS 0.33%9.8CVE-2023-20032Cisco secure endpoint classic buffer overflow vulnerabilityOn Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamA…EPSS 29%9.8CVE-2022-37434Zlib out-of-bounds write vulnerabilityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…EPSS 18%9.8CVE-2022-2274OpenSSL 3.0.4 RSA AVX512IFMA memory corruptionOpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations …EPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2023-0286), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.