Customers may report a vulnerability scan identifying CVE-2025-6942 Type confusion vulnerability in the TimeStamp Response associated with libcrypto-3-x64.dll and libssl-3-x64.dll in the following Symantec Data Loss Prevention path:
Note: The paths may differ based on the target directory selected during installation of the product.
Symantec Data Loss Prevention (DLP) Servers
Version 25.1, 26.1 and potentially others
The libcrypto-3-x64.dll and libssl-3-x64.dll are included as part of OpenSSL bundled with the DLP Servers.
Symantec DLP is not vulnerable to CVE-2025-69421.
DLP does not call the affected function, TS_RESP_verify_response(), and is not impacted.