TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2026-3336

HIGH
7.5

Beschreibung

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

CVE Details

CVSS v3.1 Bewertung7.5
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/2/2026
Zuletzt geandert3/11/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

amazon:aws-lc-sysamazon:aws_libcrypto

Schwachen (CWE)

CWE-295

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.