PT-2025-6245 · Openssl+8 · Openssl+8

·

CVE-2024-12797

·

Published

2025-02-11

·

Updated

2026-09-10

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 3.2 through 3.4
Description Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to detect that the server was not authenticated. This occurs because TLS and DTLS handshakes do not abort as expected when the SSL VERIFY PEER verification mode is set. This issue can lead to man-in-the-middle attacks if the client relies on the handshake failure to identify an authentication mismatch. RPKs are disabled by default; the issue only manifests when clients explicitly enable RPK use and the server sends an RPK instead of an X.509 certificate chain. Clients that verify the result by calling the SSL get verify result() function and take appropriate action are not affected. FIPS modules in versions 3.0 through 3.4 are not impacted.
Recommendations Update OpenSSL version 3.4 to 3.4.1 Update OpenSSL version 3.3 to 3.3.3 Update OpenSSL version 3.2 to 3.2.4 As a temporary mitigation, avoid using the SSL VERIFY PEER verification mode when relying on Raw Public Keys for server authentication, or ensure the SSL get verify result() function is called to manually verify the authentication status.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:1330
ALT-PU-2025-2674
AZL-56761
AZL-56774
AZL-78591
BDU:2025-01602
CLEANSTART-2026-AN24336
CLEANSTART-2026-AZ09261
CLEANSTART-2026-FU07345
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2024-12797
ECHO-6181-2240-677D
GHSA-79V4-65XG-PQ4G
INFSA-2025_1330
OPENSUSE-SU-2025:14802-1
PYSEC-2026-1284
RHSA-2025:1330
RHSA-2025_1330
RLSA-2025:1330
SUSE-SU-2025:02042-1
SUSE-SU-2025_02042-1
SUSE-SU-2026:3835-1
USN-7264-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu