CVE-2024-6119 Details
Description
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 3, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | [email protected] |
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openssl openssl | >= 3.0.0, < 3.0.15 >= 3.1.0, < 3.1.7 >= 3.2.0, < 3.2.3 >= 3.3.0, < 3.3.2 |
CPE
Remediation
| |
| netapp active iq unified manager | All versions |
CPE
Remediation
| |
| netapp management services for element software and netapp hci | All versions |
CPE
Remediation
| |
| netapp ontap 9 | All versions |
CPE
Remediation
| |
| netapp ontap select deploy administration utility | All versions |
CPE
Remediation
| |
| netapp ontap tools | 9 |
CPE
Remediation
| |
| netapp brocade fabric operating system | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
| netapp h610c firmware | All versions |
CPE
Remediation
| |
| netapp h610c | All versions |
CPE
Remediation
| |
| netapp h610s firmware | All versions |
CPE
Remediation
| |
| netapp h610s | All versions |
CPE
Remediation
| |
| netapp h615c | All versions |
CPE
Remediation
| |
| netapp h615c firmware | All versions |
CPE
Remediation
| |
| netapp bootstrap os | All versions |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| netapp a250 firmware | All versions |
CPE
Remediation
| |
| netapp a250 | All versions |
CPE
Remediation
| |
| netapp 500f firmware | All versions |
CPE
Remediation
| |
| netapp 500f | All versions |
CPE
Remediation
| |
| netapp c250 firmware | All versions |
CPE
Remediation
| |
| netapp c250 | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Jun 3, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 3, 2024 | CVE Modified | CISA-ADP |
| Sep 3, 2024 | New CVE Received | [email protected] |