CVE-2025-69421Disclosure(openssl / openssl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. Exploiting this issue requires an attacker to provide a malformed PKCS#12 file to an application that processes it. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-01-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-27: 1Mentions · 2026-02-19: 1Mentions · 2026-03-15: 1Mentions · 2026-06-21: 1Patch / Workaround · 2026-03-15: 101-2702-1903-1506-21
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-02-191
Disclosure1
2026-03-151
Patch1
2026-06-211
General1
Full discourse4 posts
  • BREACHSPIDER@breachspider
    General

    [CVE Analysis] CVE-2025-69421: Hitachi Energy RTU500 CMU Firmware Availability Flaw Threatens Substation Telemetry https://breachspider.com/intel/2026-06-21-cve-2025-69421-hitachi-energy-rtu500-cmu-firmware-availabili #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post announces CVE‑2025‑69421 as a firmware availability flaw in Hitachi Energy RTU500 CMU affecting substation telemetry, but provides no PoC, exploit, patch, active exploitation, or detailed technical data.

    0000067
    2.3K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-69421 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/421 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet reports that CVE-2025-69421 has been removed from AWS Lambda base images, indicating the vulnerability has been patched or otherwise mitigated.

    00000148
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-69421 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/421 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity vulnerability, CVE‑2025‑69421, affecting AWS Lambda base images that use openssl‑fips‑provider‑latest has been reported, with references to a GitHub issue and an external website, but no exploit, patch, or technical detail is provided.

    0000047
    30 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    An OSS‑Sec advisory lists several OpenSSL CVEs with severity ratings, but contains no proof‑of‑concept, exploit code, patch details, or technical specifics.

    00000156
    348 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more