Review reviewCritical

CVE-2026-31789

OpenSSL OpenSSL, SIMATIC CN 4100, openssl

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input le...

CVSS
9.8
EPSS
0.24%
15.6% percentile
CISA KEV
Not listed
Published
2026.04.08
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.24%
Technical severityCVSS 9.8

Vulnerability overview

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input le...

Affected product and versions

Product
OpenSSL OpenSSL, SIMATIC CN 4100, openssl
Affected versions
>= 3.6.0 < 3.6.2, >= 3.5.0 < 3.5.6, >= 3.4.0 < 3.4.5, >= 3.3.0 < 3.3.7, >= 3.0.0 < 3.0.20, < V5.0
Fixed versions
3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that OpenSSL OpenSSL, SIMATIC CN 4100, openssl and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-787
CVE-2026-31789 — OpenSSL OpenSSL, SIMATIC CN 4100, openssl | SECUFOCUS NOW