[UIM] CVE-2025-15467: OpenSSL Stack buffer overflow in CMS AuthEnvelopedData parsing
search cancel

[UIM] CVE-2025-15467: OpenSSL Stack buffer overflow in CMS AuthEnvelopedData parsing

book

Article ID: 428795

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

Background

A critical vulnerability, CVE-2025-15467, has been identified in OpenSSL with a CVSS score of 9.8. This issue involves a stack buffer overflow that can be triggered when parsing a CMS AuthEnvelopedData message with maliciously crafted AEAD parameters. The potential impact includes Denial of Service (crash) or, critically, remote code execution.

Is DX Unified Infrastructure Management (DX UIM / Nimsoft) affected by this vulnerability?

Exploitability

The CVE-2025-15467 vulnerability, an OpenSSL stack buffer overflow occurring during CMS AuthEnvelopedData parsing, is not exploitable within the UIM (Unified Infrastructure Management) context. This is because the vulnerability is only triggered when untrusted CMS AuthEnvelopedData (commonly found in secure email formats such as S/MIME) is processed, and UIM does not utilize CMS or S/MIME parsing. Consequently, the vulnerable code path is never executed, based on the initial analysis.

Product Components

The UIM components that utilize OpenSSL versions that fall within the vulnerable range (specifically 3.0 through 3.6) are listed below.

UIM Server Components (from 23.4 CU6):

Components OpenSSL Version
Hub 3.0.18
Controller 3.0.18
Spooler 3.0.18
hdb 3.0.18
distsrv 3.0.18
Infrastructure Manager 3.0.18
nas 3.0.18
data_engine 3.0.18
audit 3.0.18
Dr. Nimbus 3.0.18
nsa 3.0.18

Monitoring Probes:

Probe OpenSSL Version
processes 3.5.4
rsp 3.5.4
url_respone 3.5.4
dns_repsone 3.5.4
sql_respone 3.5.4
oracle 3.5.4
net_connect 3.0.18
ntevl 3.0.18
ntservices 3.0.18
mysql 3.0.18
dirscan 3.0.18
ntperf 3.0.16
cdm 3.0.16
logmon 3.0.16
sqlserver 3.0.16
sybase 3.0.16
sybase_rs 3.0.16
dhcp_response 3.0.16
nexec 3.0.16
adevl 3.0.16
cluster 3.0.16
perfmon 3.0.16
printer 3.0.16
emailgtw 3.0.13
iis 3.0.13
printer 3.0.13
db2 3.0.13
cisco_ucm 3.0.11

Environment

Release: DX UIM

Resolution

Remediation Plan

UIM Core components using OpenSSL will be upgraded to version 3.5.5 in the upcoming 23.4 CU7 release, scheduled for the first week of March 2026.

The affected monitoring probes will be updated to OpenSSL 3.5.5. The ETAs for these probe updates will be provided soon, as the development team is currently working on them.