PT-2026-82595 · Unknown · Openssl-Encrypt
CVE-2026-81694
·
Published
2026-08-27
·
Updated
2026-09-03
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
openssl-encrypt versions prior to 1.4.9
Description
The software fails to sanitize filenames read from untrusted drive data located outside the AES-GCM authenticated manifest before displaying them in the output of the
verify-usb command. An attacker can use filenames containing terminal cursor-movement and erase-line control bytes to repaint a forged PASSED verdict on the screen, which masks actual tamper detection.Recommendations
Update to version 1.4.9.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt