CVE-2024-53846 - CVE House
Back to Database
Status published Medium CVE-2024-53846

ssl fails to validate incorrect extened key usage

Vulnerability Description

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27.0, resulting in a server or client verifying the peer when incorrect extended key usage is presented (i.e., a server will verify a client if they have server auth ext key usage and vice versa).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-53846

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

otp
Vulnerable Versions:
>= 25.3.2.8, <= 25.3.2.16, >= 26.2, <= 26.2.5.6, >= 27.0, <= 27.1.3

Timeline

Official Publish: December 5th, 2024
Last Modified: December 6th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

Weaknesses (CWE)