Vulnerability record · CVE-2024-6119 · published 3 September 2024
CVE-2024-6119: OpenSSL certificate name check type confusion causes denial of service
OOpenssl · Openssl
OpenSSL applications that perform certificate name checks can read an invalid memory address when comparing an expected name against an otherName subject alternative name in an X.509 certificate. This triggers an exception that terminates the process, causing a denial of service. Basic chain validation is unaffected; the crash requires the application to also specify an expected DNS name, email address or IP address.
Description
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network reachability and no privileges or interaction required, plus a very high EPSS score, though impact is limited to denial of service and no in-the-wild exploitation is confirmed.
What it is
OpenSSL applications that perform certificate name checks can read an invalid memory address when comparing an expected name against an otherName subject alternative name in an X.509 certificate. This triggers an exception that terminates the process, causing a denial of service. Basic chain validation is unaffected; the crash requires the application to also specify an expected DNS name, email address or IP address.
Impact
An attacker who can present a crafted certificate to a name-checking application can crash that process, denying service to legitimate users. There is no memory corruption or code execution described, only abnormal termination.
Attack surface
Reached over the network by supplying a malicious X.509 certificate to a client or other application that performs name checks against an expected identity. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), though the target must be configured to check names, which TLS servers generally do not do.
Exploitation
Not listed in CISA KEV and no ransomware use documented. EPSS is high (0.66582, 99.25th percentile), and public patches and vendor advisories exist, so exploitation is plausible but no in-the-wild activity is confirmed by this record.
What to do
- Upgrade OpenSSL to a version containing the fixes referenced in the patch commits (05f360d9, 06d1dc3f, 621f3729, 7dfcee2c).
- Apply vendor advisories for NetApp and Siemens products that bundle the affected OpenSSL versions.
- Where immediate patching is not possible, avoid configuring applications to perform name checks against an expected identity on untrusted certificates.
- Monitor for process crashes in TLS clients and other name-checking services and treat repeated crashes as potential exploitation attempts.
Detection
- Alert on abnormal termination or crash logs from TLS clients and services that perform certificate name checks.
- Inspect X.509 certificates for otherName subject alternative name entries and flag them for review in certificate monitoring.
- Correlate crash events with inbound TLS connections presenting certificates containing otherName SANs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-6119 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-6119), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.