CVE-2021-43527

Modified
Published: 08 Dec 2021, 00:00
Last modified:04 Aug 2024, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
5.24% LOW
5% probability -0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Dec 2021, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 03:55
Last Modified
Vulnerability information updated

Description

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 5.24% Percentile: 90%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • mozillanss

    < 3.73 | ≥ unspecified, < 3.73 | ≥ unspecified, < 3.68.1

  • mozillanss_esr

    < 3.68.1

  • netappcloud_backup

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.1

  • oraclecommunications_cloud_native_core_binding_support_function

    1.11.0

  • oraclecommunications_cloud_native_core_network_repository_function

    1.15.0 | 1.15.1

  • oraclecommunications_cloud_native_core_network_slice_selection_function

    1.8.0

  • oraclecommunications_policy_management

    12.6.0.0.0

  • starwindsoftwarestarwind_san_\&_nas

    v8r13

  • starwindsoftwarestarwind_virtual_san

    v8r13:14398

References (9)