Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-2975

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
14/07/2023
Última modificación:
23/04/2025

Descripción

*** Pendiente de traducción *** Issue summary: The AES-SIV cipher implementation contains a bug that causes<br /> it to ignore empty associated data entries which are unauthenticated as<br /> a consequence.<br /> <br /> Impact summary: Applications that use the AES-SIV algorithm and want to<br /> authenticate empty data entries as associated data can be misled by removing,<br /> adding or reordering such empty entries as these are ignored by the OpenSSL<br /> implementation. We are currently unaware of any such applications.<br /> <br /> The AES-SIV algorithm allows for authentication of multiple associated<br /> data entries along with the encryption. To authenticate empty data the<br /> application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with<br /> NULL pointer as the output buffer and 0 as the input buffer length.<br /> The AES-SIV implementation in OpenSSL just returns success for such a call<br /> instead of performing the associated data authentication operation.<br /> The empty data thus will not be authenticated.<br /> <br /> As this issue does not affect non-empty associated data authentication and<br /> we expect it to be rare for an application to use empty associated data<br /> entries this is qualified as Low severity issue.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.0.0 (incluyendo) 3.0.9 (incluyendo)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.1.0 (incluyendo) 3.1.1 (incluyendo)
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*