CVE-2024-13454: Weak Encryption
Published Jan 20, 2025
·Updated
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3
Affected Software
3 affected components
Easy-RSA Easy-RSA>=3.0.5<=3.1.7
OpenSSL OpenSSL
OpenVPN Easy-rsa>=3.0.5<=3.1.7
Event History
Jan 20, 2025
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13454?
CVE-2024-13454 is considered a medium severity vulnerability due to its potential to allow local attackers to brute force private CA keys.
2
How do I fix CVE-2024-13454?
To fix CVE-2024-13454, upgrade your Easy-RSA version to 3.1.8 or later which addresses the weak encryption algorithm.
3
Which versions are affected by CVE-2024-13454?
CVE-2024-13454 affects Easy-RSA versions 3.0.5 through 3.1.7.
4
Can CVE-2024-13454 be exploited remotely?
CVE-2024-13454 cannot be exploited remotely as it requires local access to the system.
5
What components does CVE-2024-13454 impact?
CVE-2024-13454 impacts the Easy-RSA tool when it uses OpenSSL 3 for creating CA keys.