CVE-2023-31421
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.
Published:Oct 26, 2023
Last Modified:Nov 21, 2024
EPS:Oct 26, 2023
EPSS Score:0.00093
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Elastic
Product
Apm Server
Elastic
Apm Server
Vendor
Elastic
Product
Elastic Agent
Elastic
Elastic Agent
Vendor
Elastic
Product
Elastic Beats
Elastic
Elastic Beats
Vendor
Elastic
Product
Elastic Fleet Server
Elastic
Elastic Fleet Server
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
