QID 377734

Date Published: 2022-11-10

QID 377734: Erlang Client Authentication Bypass Vulnerability

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
QID Detection Logic:
Authenticated (Unix):
This QID uses command cat $(dirname $(dirname `which erl`)/$(readlink `which erl`))/../releases/*/OTP_VERSION; to check the install version.

Successful exploitation could compromise confidentiality, integrity and availability of the system

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Please refer to the following links 1854

    CVEs related to QID 377734

    Software Advisories
    Advisory ID Software Component Link
    otp-25-1-released URL Logo erlangforums.com/t/otp-25-1-released/1854