CVE-2022-46505

An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrixssl:matrixssl:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:30

Type Values Removed Values Added
References () https://github.com/SmallTown123/details-for-CVE-2022-46505 - Exploit, Third Party Advisory () https://github.com/SmallTown123/details-for-CVE-2022-46505 - Exploit, Third Party Advisory
References () https://smalltown123.notion.site/MatrixSSL-session-resume-bug-a0 - Permissions Required, Vendor Advisory () https://smalltown123.notion.site/MatrixSSL-session-resume-bug-a0 - Permissions Required, Vendor Advisory
Summary
  • (es) Un problema en MatrixSSL 4.5.1-open y versiones anteriores provoca que no se pueda verificar de forma segura el campo SessionID, lo que resulta en el uso indebido de un MasterSecret completamente cero que puede descifrar datos secretos.

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-862 CWE-665

Information

Published : 2023-01-18 16:15

Updated : 2024-11-21 07:30


NVD link : CVE-2022-46505

Mitre link : CVE-2022-46505

CVE.ORG link : CVE-2022-46505


JSON object : View

Products Affected

matrixssl

  • matrixssl
CWE
CWE-665

Improper Initialization