Symantec DLP and CVE-2025-69421 OpenSSL Vulnerability
search cancel

Symantec DLP and CVE-2025-69421 OpenSSL Vulnerability

book

Article ID: 452075

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

Customers may report a vulnerability scan identifying CVE-2025-6942 Type confusion vulnerability in the TimeStamp Response associated with libcrypto-3-x64.dll and libssl-3-x64.dll in the following Symantec Data Loss Prevention path:

  • \program files\symantec\datalossprevention\serverplatformcommon\26.1.00000\protect\lib\native\libcrypto-3-x64.dll
  • \program files\symantec\datalossprevention\\serverplatformcommon\26.1.00000\protect\lib\native\libssl-3-x64.dll

Note: The paths may differ based on the target directory selected during installation of the product.

Environment

Symantec Data Loss Prevention (DLP) Servers

Version 25.1, 26.1 and potentially others

Cause

The libcrypto-3-x64.dll and libssl-3-x64.dll are included as part of OpenSSL bundled with the DLP Servers.

Resolution

Symantec DLP is not vulnerable to CVE-2025-69421.

DLP does not call the affected function, TS_RESP_verify_response(), and is not impacted.