Tenable.sc Report: OpenSSL 3.0.0 < 3.0.15 Vulnerability

Customers using Tenable solutions for scanning vulnerabilities may receive a critical alert when scanning products using Apache httpd server with OpenSSL version lower than 3.0.15.

This report pertains to CVE-2024-5535.

However, the OpenSSL team rates this CVE as low severity.

Atempo products are not directly impacted by this CVE as they do not use the vulnerable SSL_select_next_proto API.

The OpenSSL team plans to deliver a fix in a future 3.0.15 release, which is not yet available.

The effective impact of this CVE on Apache httpd server is currently unknown, as we await further communication from Apache.

References

https://www.tenable.com/plugins/nessus/201085

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535

https://nvd.nist.gov/vuln/detail/CVE-2024-5535

https://openssl-library.org/news/secadv/20240627.txt

https://openssl-library.org/news/openssl-3.0-notes/

Contact




    Skip to content