CVE-2024-13454

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 20, 2025
Updated: Jan 21, 2025
CWE ID 326

Summary

CVE-2024-13454 is a vulnerability affecting Easy-RSA versions 3.0.5 through 3.1.7. This issue stems from the use of a weak encryption algorithm during the creation of private CA keys using OpenSSL 3. The vulnerability enables local attackers to more effectively carry out brute force attacks, increasing the risk of unauthorized access to encryption keys and potential data breaches. It is crucial for affected organizations to update their Easy-RSA installations to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share