CVE-2021-3449

Aliases:GHSA-83mx-573x-5rw9BIT-node-2021-3449BIT-node-min-2021-3449RUSTSEC-2021-0055
Modified
Published: 25 Mar 2021, 14:25
Last modified:17 Sept 2024, 03:43

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
5.9 MEDIUM
v3.1 (nvd)
EPSS Score
9.86% LOW
10% probability -1.40%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Mar 2021, 14:25
Published
Vulnerability first disclosed
17 Sept 2024, 03:43
Last Modified
Vulnerability information updated

Description

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 9.86% Percentile: 93%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • Crates.Ioopenssl-src

    < 111.15.0 | ≥ 0.0.0-0, < 111.15.0

  • checkpointmulti-domain_management_firmware

    r80.40 | r81

  • checkpointquantum security gateway

    r80.40 | r81

  • checkpointquantum security management

    r80.40 | r81

  • debiandebian_linux

    9.0 | 10.0

  • fedoraprojectfedora

    34

  • freebsdfreebsd

    12.2 | 12.2:p1 | 12.2:p2

  • mcafeeweb_gateway

    8.2.19 | 9.2.10 | 10.1.1

  • mcafeeweb_gateway_cloud_service

    8.2.19 | 9.2.10 | 10.1.1

  • netappactive_iq_unified_manager

    na

  • netappcloud_volumes_ontap_mediator

    na

  • netappe-series_performance_analyzer

    na

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappontap_select_deploy_administration_utility

    na

  • netappsantricity_smi-s_provider

    na

  • netappsnapcenter

    na

  • netappstoragegrid

    na

  • nodejsnode.js

    ≥ 10.0.0, ≤ 10.12.0 | ≥ 10.13.0, ≤ 10.24.0 | ≥ 12.0.0, ≤ 12.12.0 | ≥ 12.13.0, < 12.22.1 | ≥ 14.0.0, ≤ 14.14.0 | ≥ 14.15.0, < 14.16.1 | ≥ 15.0.0, < 15.14.0

  • UnknownOpenSSL

    ≥ 1.1.1, < 1.1.1k | Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j)

  • oraclecommunications_communications_policy_management

    12.6.0.0.0

  • oracleenterprise_manager_for_storage_management

    13.4.0.0

  • oracleessbase

    21.2

  • oraclegraalvm

    19.3.5 | 20.3.1.2 | 21.0.0.2

  • oraclejd_edwards_enterpriseone_tools

    < 9.2.6.0

  • oraclejd_edwards_world_security

    a9.4

  • oraclemysql_connectors

    ≤ 8.0.23

  • oraclemysql_server

    ≤ 5.7.33 | ≥ 8.0.15, ≤ 8.0.23

  • oraclemysql_workbench

    ≤ 8.0.23

  • oraclepeoplesoft_enterprise_peopletools

    8.57 | 8.58 | 8.59

  • oracleprimavera_unifier

    ≥ 17.7, ≤ 17.12 | 19.12 | 20.12 | 21.12

  • oraclesecure_backup

    < 18.1.0.1.0

  • oraclesecure_global_desktop

    5.6

  • oraclezfs_storage_appliance_kit

    8.8

  • siemensruggedcom_rcm1224_firmware

    ≥ 6.2

  • siemensscalance_m-800_firmware

    ≥ 6.2

  • siemensscalance_s602

    ≥ 4.1

  • siemensscalance_s612

    ≥ 4.1

  • siemensscalance_s615_firmware

    ≥ 6.2

  • siemensscalance s623

    ≥ 4.1

  • siemensscalance s627-2m

    ≥ 4.1

  • siemensscalance_sc-600_firmware

    ≥ 2.0

  • siemensscalance_w1700_firmware

    ≥ 2.0

  • siemensscalance_w700_firmware

    ≥ 6.5

  • siemensscalance_xb-200_firmware

    < 4.3

  • siemensscalance_xc-200_firmware

    < 4.3

  • siemensscalance_xf-200ba_firmware

    < 4.3

  • siemensscalance_xm-400_firmware

    < 6.4

  • siemensscalance_xp-200_firmware

    < 4.3

  • siemensscalance xr-300wg

    < 4.3

Showing first 50 affected entries in server-rendered view.

References (38)