« Volver al listado

CVE-2026-31790

Estado: ModificadaAlta (7.5)—

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.

Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.

RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.

Leer descripción completaMostrar menos

If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.

As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.

The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota (AV:N, PR:N, UI:N) en OpenSSL que expone datos no inicializados de memoria. Acceso red sin autenticación permite lectura de información sensible previa de la aplicación.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-31790",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-31790",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-08T14:32:04.700201Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "openssl-security@openssl.org",
      "affectedData": [
        {
          "vendor": "OpenSSL",
          "product": "OpenSSL",
          "versions": [
            {
              "status": "affected",
              "version": "3.6.0",
              "lessThan": "3.6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.5.0",
              "lessThan": "3.5.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.4.0",
              "lessThan": "3.4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.3.0",
              "lessThan": "3.3.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.0.0",
              "lessThan": "3.0.20",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "SIMATIC CN 4100",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V5.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-04-07T22:16:21.770",
  "references": [
    {
      "url": "https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac",
      "tags": [
        "Patch"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482",
      "tags": [
        "Patch"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406",
      "tags": [
        "Patch"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790",
      "tags": [
        "Patch"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e",
      "tags": [
        "Patch"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://openssl-library.org/news/secadv/20260407.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "openssl-security@openssl.org"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "openssl-security@openssl.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue."
    },
    {
      "lang": "es",
      "value": "Resumen del problema: Las aplicaciones que utilizan la encapsulación de clave RSASVE para establecer una clave de cifrado secreta pueden enviar el contenido de un búfer de memoria no inicializado a un par malicioso.\n\nResumen del impacto: El búfer no inicializado podría contener datos sensibles de la ejecución anterior del proceso de la aplicación, lo que lleva a la fuga de datos sensibles a un atacante.\n\nRSA_public_encrypt() devuelve el número de bytes escritos en caso de éxito y -1 en caso de error. El código afectado solo prueba si el valor de retorno no es cero. Como resultado, si el cifrado RSA falla, la encapsulación aún puede devolver éxito al llamador, establecer las longitudes de salida y dejar que el llamador use el contenido del búfer de texto cifrado como si se hubiera producido un texto cifrado KEM válido.\n\nSi las aplicaciones usan EVP_PKEY_encapsulate() con RSA/RSASVE en una clave pública RSA inválida proporcionada por un atacante sin validar primero esa clave, entonces esto puede causar que el contenido obsoleto o no inicializado del búfer de texto cifrado proporcionado por el llamador sea divulgado al atacante en lugar del texto cifrado KEM.\n\nComo solución alternativa, llamar a EVP_PKEY_public_check() o EVP_PKEY_public_check_quick() antes de EVP_PKEY_encapsulate() mitigará el problema.\n\nLos módulos FIPS en 3.6, 3.5, 3.4, 3.3, 3.1 y 3.0 se ven afectados por este problema."
    }
  ],
  "lastModified": "2026-07-24T23:10:00.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B28A8143-89A4-4332-A1F8-A65FB5AA829F",
              "versionEndExcluding": "3.0.20",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF303B21-D9BF-461D-B7B0-A3FE1D557A9F",
              "versionEndExcluding": "3.3.7",
              "versionStartIncluding": "3.3.0"
            },
            {
              "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCCE43D0-8F17-475D-9EE6-842F758A9905",
              "versionEndExcluding": "3.4.5",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6BC0271-444D-4597-BF05-DC60034EAA49",
              "versionEndExcluding": "3.5.6",
              "versionStartIncluding": "3.5.0"
            },
            {
              "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A9E621D-29D8-418A-BF37-BED333C14507",
              "versionEndExcluding": "3.6.2",
              "versionStartIncluding": "3.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "openssl-security@openssl.org"
}