<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:25:49.573738+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1065</id>
    <title>ALSA-2022:1065 — Important: openssl security update</title>
    <updated>2026-10-02T15:25:49.709419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: openssl, AlmaLinux:8: openssl-devel, AlmaLinux:8: openssl-libs, AlmaLinux:8: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01315</id>
    <title>bdu:2022-01315</title>
    <updated>2026-10-02T15:25:49.709509+00:00</updated>
    <content>bdu:2022-01315</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-0778</id>
    <title>Withdrawn: BELL-CVE-2022-0778 — CVE-2022-0778 does not affect BellSoft software</title>
    <updated>2026-10-02T15:25:49.709529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-0778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mariadb-2022-0778</id>
    <title>BIT-mariadb-2022-0778 — Infinite loop in BN_mod_sqrt() reachable when parsing certificates</title>
    <updated>2026-10-02T15:25:49.709544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mariadb</p>
<p>The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mariadb-2022-0778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-250</id>
    <title>certfr-2022-avi-250 — Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un
attaquant de provoquer un déni de service à distance.</title>
    <updated>2026-10-02T15:25:49.709579+00:00</updated>
    <content>certfr-2022-avi-250</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</id>
    <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
    <updated>2026-10-02T15:25:49.709594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: openssl</p>
<p>Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-68614</id>
    <title>cnvd-2022-68614</title>
    <updated>2026-10-02T15:25:49.709617+00:00</updated>
    <content>cnvd-2022-68614</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-68614"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320096</id>
    <title>EUVD-2026-320096</title>
    <updated>2026-10-02T15:25:49.709628+00:00</updated>
    <content>EUVD-2026-320096</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-0778</id>
    <title>fkie_cve-2022-0778</title>
    <updated>2026-10-02T15:25:49.709638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-0778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x3mh-jvjw-3xwx</id>
    <title>GHSA-x3mh-jvjw-3xwx — openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates</title>
    <updated>2026-10-02T15:25:49.709669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: openssl-src</p>
<p>The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x3mh-jvjw-3xwx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-0778</id>
    <title>gsd-2022-0778</title>
    <updated>2026-10-02T15:25:49.709701+00:00</updated>
    <content>gsd-2022-0778</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-0778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-132-02</id>
    <title>ICSA-22-132-02 — Mitsubishi Electric MELSOFT iQ AppPortal</title>
    <updated>2026-10-02T15:25:49.709712+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache HTTP Server Versions 2.4.0 to 2.4.46 allow unprivileged local users to stop httpd on Windows.CVE-2020-13938 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). In Apache HTTP Server Versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow.CVE-2021-26691 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server Versions 2.4.48 and earlier.CVE-2021-34798 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). An attacker who can present SM2 content for decryption to an application could cause data to overflow the buffer up to a maximum of 62 bytes, altering the contents of other data held after the buffer or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1 (Affected 1.1.1-1.1.1k). This issue is detailed further in CVE-2021-3711.CVE-2021-3711 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). A carefully crafted request body can ca…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-132-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-0778</id>
    <title>msrc_CVE-2022-0778 — Infinite loop in BN_mod_sqrt() reachable when parsing certificates</title>
    <updated>2026-10-02T15:25:49.709752+00:00</updated>
    <content>msrc_CVE-2022-0778</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-0778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0112</id>
    <title>NCSC-2026-0112 — Kwetsbaarheden verholpen in Siemens producten</title>
    <updated>2026-10-02T15:25:49.709768+00:00</updated>
    <content>NCSC-2026-0112</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1603</id>
    <title>OESA-2022-1603 — openssl security update</title>
    <updated>2026-10-02T15:25:49.709813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: openssl, openEuler:20.03-LTS-SP2: openssl, openEuler:20.03-LTS-SP3: openssl</p>
<p>Cryptography and SSL/TLS Toolkit.

Security Fix(es):

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the openssl 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1603"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0856-1</id>
    <title>openSUSE-SU-2022:0856-1 — Security update for openssl-1_0_0</title>
    <updated>2026-10-02T15:25:49.709847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-1_0_0</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0856-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1071</id>
    <title>RHSA-2022:1071 — Red Hat Security Advisory: openssl security update</title>
    <updated>2026-10-02T15:25:49.709864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2022-0014</id>
    <title>RUSTSEC-2022-0014 — Infinite loop in `BN_mod_sqrt()` reachable when parsing certificates</title>
    <updated>2026-10-02T15:25:49.709880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: openssl-src</p>
<p>The `BN_mod_sqrt()` function, which computes a modular square root, contains
a bug that can cause it to loop forever for non-prime moduli.</p>
<p>Internally this function is used when parsing certificates that contain
elliptic curve public keys in compressed form or explicit elliptic curve
parameters with a base point encoded in compressed form.</p>
<p>It is possible to trigger the infinite loop by crafting a certificate that
has invalid explicit curve parameters.</p>
<p>Since certificate parsing happens prior to verification of the certificate
signature, any process that parses an externally supplied certificate may thus
be subject to a denial of service attack. The infinite loop can also be
reached when parsing crafted private keys as they can contain explicit
elliptic curve parameters.</p>
<p>Thus vulnerable situations include:</p>
<p>- TLS clients consuming server certificates
 - TLS servers consuming client certificates
 - Hosting providers taking certificates or private keys from customers
 - Certificate authorities parsing certification requests from subscribers
 - Anything else which parses ASN.1 elliptic curve parameters</p>
<p>Also any other applications that use the `BN_mod_sqrt()` where the attacker
can control the parameter values are vulnerable to this DoS issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2022-0014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2022-0012</id>
    <title>SCA-2022-0012 — OpenSSL vulnerability affects multiple SICK SIMs</title>
    <updated>2026-10-02T15:25:49.709910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In March 2022, the OpenSSL development team disclosed a denial of service in versions "3.0.0," "3.0.1," "1.1.1"-"1.1.1m" and "1.0.2-1.0.2zc" of the OpenSSL library. Exploiting this vulnerability allows remote, unauthenticated attackers to cause an infinite loop. It is possible to trigger the infinite loop by creating a certificate that has invalid explicit curve parameters or when parsing created private keys, as they may contain explicit elliptic curve parameters. It may be possible to put the SIMs in a non-responsive state since 100% of the CPU resource is consumed by the infinite loop calculation.
The listed SICK SIM products are currently operated with an OpenSSL version that is vulnerable to CVE-2022-0778. With that it could be possible to exploit the mentioned vulnerability if the SIM devices are connected to a network with untrusted devices. 
In that case an untrusted client may send a manipulated SSH-certificate to the SIM, which exploits the vulnerability in the OpenSSL library as described above when it comes to the certificate validation by the SIM product. 
Evaluation is undergoing.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2022-0012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019200</id>
    <title>SSA-019200 — SSA-019200: Multiple Vulnerabilities in SCALANCE W-700 IEEE 802.11n Devices Before V6.6.0</title>
    <updated>2026-10-02T15:25:49.709935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets. An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol. An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragme…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019200"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2022:0861-1</id>
    <title>SUSE-RU-2022:0861-1 — Security update for openssl-1_1</title>
    <updated>2026-10-02T15:25:49.709991+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-1_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2022:0861-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0778</id>
    <title>UBUNTU-CVE-2022-0778</title>
    <updated>2026-10-02T15:25:49.710007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl, Ubuntu:20.04:LTS: openssl, Ubuntu:20.04:LTS: edk2 and 5 more</p>
<p>The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-013</id>
    <title>VDE-2022-013 — PHOENIX CONTACT: Multiple products affected by possible infinite loop within OpenSSL library</title>
    <updated>2026-10-02T15:25:49.710058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>FL MGUARD and TC MGUARD devices are affected by a possible infinite loop within a OpenSSL library method for parsing elliptic curve parameters. This method is used on parsing cryptographic certificates that contain elliptic curve public keys in compressed form, which may occur on:</p>
<p>Parsing client certificates for HTTPS administrative login
Parsing client certificates for SSH administrative login
Parsing peer certificates for IPsec VPN connections
Parsing certificates of external servers, including:
OpenVPN server
Configuration pull server
Update server
Attackers could try to exploit the vulnerability from remote.
For the mGuard Device Manager only the mdm Installer for Windows is affected.</p>
<p>UPDATE A: Added FL MGUARD 1102 and FL MGUARD 1105:</p>
<p>On FL MGUARD 1102 and FL MGUARD 1105 with mGuardNT 1.5.2 and older, the device can
be affected through an adapted certificate. This can occur on connection with a remote logging
server, configured for certificate authentication, or an remote authentication server at certificate
based authentication.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0065</id>
    <title>WID-SEC-W-2022-0065 — OpenSSL: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T15:25:49.710083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0065"/>
  </entry>
</feed>
