Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37026


In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.


Published

2022-09-21T14:15:11.223

Last Modified

2025-05-27T19:15:22.210

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application erlang erlang\/otp < 23.3.4.15 Yes
Application erlang erlang\/otp < 24.3.4.2 Yes
Application erlang erlang\/otp < 25.0.2 Yes

References