HOMEVULNERABILITIESCVE-2020-1971
MEDIUM

CVE-2020-1971

CWE-476Published: December 8, 2020· Updated: Jun 17, 2026

5.9
CVSS v3.1

Official Description

The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).

NVD Source

Technical Analysis

CVE-2020-1971 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in availability disruption (denial of service), with a CVSS base score of 5.9.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityHigh
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityNone
IntegrityNone
AvailabilityHigh
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Vendors & Products

Debian1 product(s)
debian linux
Fedora1 product(s)
fedora
netapp18 product(s)
active iq unified managerclustered data ontap antivirus connectordata ontape-series santricity os controllerhci management nodemanageability software development kitoncommand insightoncommand workflow automationplug-in for symantec netbackupsantricity smi-s providersnapcentersolidfire+6
Node.js1 product(s)
node.js
OpenSSL1 product(s)
openssl
Oracle21 product(s)
api gatewaybusiness intelligencecommunications cloud native core network function cloud native environmentcommunications diameter intelligence hubcommunications session border controllercommunications session routercommunications subscriber-aware load balancercommunications unified session managerenterprise communications brokerenterprise manager base platformenterprise manager for storage managemententerprise manager ops center+9
siemens1 product(s)
sinec infrastructure network services
tenable2 product(s)
log correlation enginenessus network monitor
Source: NVD CPE · 65 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (52)

Quick Facts

CVE IDCVE-2020-1971
CVSS Score5.9 / 10
SeverityMEDIUM
WeaknessCWE-476
CISA KEVNo
Affected8 vendor(s)
PublishedDec 8, 2020

Related CVEs (CWE-476)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2020-1971 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.