Looking for the vulnerability index of Invicti's legacy products?
OpenSSL NULL Pointer Dereference Vulnerability - CVE-2025-69421 - Vulnerability Database

OpenSSL NULL Pointer Dereference Vulnerability - CVE-2025-69421

High
Reference: CVE-2025-69421
Title: OpenSSL NULL Pointer Dereference Vulnerability
Overview:

Issue summary: Processing a malformed PKCS12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS12 file this parameter can be NULL causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6 3.5 3.4 3.3 and 3.0 are not affected by this issue as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6 3.5 3.4 3.3 3.0 1.1.1 and 1.0.2 are vulnerable to this issue.