[WID-SEC-2026-3005] OpenSSL: Mehrere Schwachstellen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 25.08.2026 Stand 26.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung OpenSSL ist eine im Quelltext frei verfügbare Bibliothek, die Secure Sockets Layer (SSL) und Transport Layer Security (TLS) implementiert. Produkte 25.08.2026 Debian Linux Open Source OpenSSL <4.0.2 Open Source OpenSSL <3.6.4 Open Source OpenSSL <3.5.8 Open Source OpenSSL <3.4.7 Open Source OpenSSL <3.0.22 Open Source OpenSSL <1.1.1zi Open Source OpenSSL <1.0.2zr Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in OpenSSL (CVSS Base Score 7.5) can be exploited by a remote attacker to bypass security controls, manipulate or expose data, or cause a denial-of-service condition. Affected versions include OpenSSL 4.x prior to 4.0.2, 3.x prior to 3.6.4, 3.5.8, and 3.4.7, 3.0.x prior to 3.0.22, 1.1.1 prior to 1.1.1zi, and 1.0.2 prior to 1.0.2zr. A mitigation is available, though specific patch versions are not detailed in the advisory.