VYPR
Critical severity9.8NVD Advisory· Published Apr 15, 2023· Updated Jun 17, 2026

CVE-2021-46880

CVE-2021-46880

Description

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • OpenBSD/Libressl2 versions
    cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*range: <3.4.2
    • (no CPE)range: <3.4.2
  • OpenBSD/OpenBSD2 versions
    cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*range: <7.0
    • (no CPE)range: <7.0 errata 006
  • LibreSSL/LibreSSLdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.