CVE-2024-7346

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full TLS certificate validation is needed for network security.  The existing certificates should be replaced with CA-signed certificates from a recognized certificate authority that contain the necessary information to support host name validation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*

History

05 Sep 2024, 14:03

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 4.8
CWE CWE-287
CPE cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:*
First Time Progress
Progress openedge
Summary
  • (es) La validación del nombre de host para los certificados TLS se omite cuando se utilizan los certificados predeterminados de OpenEdge instalados para realizar el protocolo de enlace TLS para una conexión en red. Esto se ha corregido para que los certificados predeterminados ya no puedan anular la validación del nombre de host y deban reemplazarse cuando se necesite una validación completa del certificado TLS para la seguridad de la red. Los certificados existentes deben reemplazarse con certificados firmados por una autoridad de certificación reconocida que contengan la información necesaria para admitir la validación del nombre de host.
References () https://community.progress.com/s/article/Client-connections-using-default-TLS-certificates-from-OpenEdge-may-bypass-TLS-host-name-validation - () https://community.progress.com/s/article/Client-connections-using-default-TLS-certificates-from-OpenEdge-may-bypass-TLS-host-name-validation - Mitigation, Vendor Advisory

03 Sep 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-03 15:15

Updated : 2024-09-05 14:03


NVD link : CVE-2024-7346

Mitre link : CVE-2024-7346

CVE.ORG link : CVE-2024-7346


JSON object : View

Products Affected

progress

  • openedge
CWE
CWE-287

Improper Authentication

CWE-297

Improper Validation of Certificate with Host Mismatch