# OpenSSL DoS flaw crashes servers and clients

Published: 2020-04-22 · Severity: high
Canonical: https://vorant.io/reports/8456215e-0d87-4e5f-b4ed-f9982af9c426/openssl-dos-flaw-crashes-servers-and-clients

> OpenSSL vulnerability allows denial-of-service attacks that can crash server and client applications; users urged to apply vendor patches immediately.

The Information-technology Promotion Agency (IPA) of Japan has issued an advisory concerning a denial-of-service vulnerability in OpenSSL, the widely-used open-source library that provides SSL and TLS functionality. The vulnerability affects both server and client applications running OpenSSL and can be exploited to cause application crashes.

The IPA characterizes this as a potentially escalating threat and strongly recommends immediate remediation. Organizations are advised to apply vendor-provided patches as soon as possible. The advisory directs users to vendor resources for version-specific remediation guidance, noting that IPA cannot provide support for individual system configurations.

This advisory was published on April 23, 2020, and represents a routine but important notification to the Japanese information-security community about a critical infrastructure component. Given OpenSSL's ubiquitous deployment in web servers, VPNs, email systems, and countless other applications, the potential attack surface is substantial.

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2020/alert20200423.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8456215e-0d87-4e5f-b4ed-f9982af9c426/openssl-dos-flaw-crashes-servers-and-clients.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
