CVE-2026-28390
OpenSSL OpenSSL, SIMATIC CN 4100, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem 취약점
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field i...
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 1.03% 백분위 60.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.08