CVE-2024-13454
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 20, 2025
Updated: Jan 21, 2025
CWE ID 326
Summary
CVE-2024-13454 is a vulnerability affecting Easy-RSA versions 3.0.5 through 3.1.7. This issue stems from the use of a weak encryption algorithm during the creation of private CA keys using OpenSSL 3. The vulnerability enables local attackers to more effectively carry out brute force attacks, increasing the risk of unauthorized access to encryption keys and potential data breaches. It is crucial for affected organizations to update their Easy-RSA installations to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.