CVE-2026-45445: AES-OCB IV Flaw in OpenSSL on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-45445 is a cryptographic vulnerability in OpenSSL’s AES-OCB mode where the Initialisation Vector (IV) is silently ignored when encryption or decryption is performed via the EVP_Cipher() API path. This means data intended to be protected with a unique IV may be encrypted with a predictable or reused nonce, undermining the confidentiality and integrity guarantees of AES-OCB. Any Azure service or workload relying on OpenSSL’s EVP_Cipher() with AES-OCB mode is potentially at risk of ciphertext forgery or plaintext recovery. ...

13 June 2025 Â· ZX Cloud Security

CVE-2023-5678 OpenSSL DH DoS Flaw Affects Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2023-5678 is a vulnerability in OpenSSL where processing a Diffie-Hellman (DH) key or parameter with an excessively large Q value can cause the application to hang, consuming significant CPU time. This creates a denial-of-service risk for any service that processes externally supplied DH parameters. Microsoft has published guidance via the MSRC as it affects components within the Azure ecosystem. Security Architect’s Take: Review any Azure services or workloads using OpenSSL for TLS/cryptographic operations and ensure OpenSSL is patched to a version addressing CVE-2023-5678. Pay particular attention to services that accept client-supplied DH parameters, and consider disabling legacy DH cipher suites where not required. ...

13 June 2024 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. Learn more