CVE Explorer
CVE-2026-2673
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected
preferred key exchange group when its key exchange group configuration includes
the default by using the 'DEFAULT' keyword.
Impact summary: A less preferred key exchange may be used even when a more
preferred group is supported by both client and server, if the group
was not included among the client's initial predicated keyshares.
This will sometimes be the case with the new hybrid post-quantum groups,
if the client ch
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"3.6.2","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.6","status":"affected","version":"3.5.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/cna/affected/0
{"defaultStatus":"unknown","product":"SIMATIC CN 4100","vendor":"Siemens","versions":[{"lessThan":"V5.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/adp/2/affected/0
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"3.6.2","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.6","status":"affected","version":"3.5.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/cna/affected/0
{"defaultStatus":"unknown","product":"SIMATIC CN 4100","vendor":"Siemens","versions":[{"lessThan":"V5.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/adp/2/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-757","description":"CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/03/13/3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/adp/0/references/0
{"url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/adp/2/references/0
{"name":"3.6.2 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/cna/references/1
{"name":"3.5.6 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/cna/references/2
{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260313.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1f8ca04f91b069aa828cff6ec053df1dc593652d45bde7b6e8e6ad81676b108d · sha256:e537adb4d027d55a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.