SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3449

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.

MEDIUM 5.9EPSS 62.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 62.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
62.91% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
openssl/openssl · debian/debian linux · freebsd/freebsd · netapp/active iq unified manager · netapp/cloud volumes ontap mediator · netapp/e-series performance analyzer · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/ontap select deploy administration utility · netapp/santricity smi-s provider · netapp/snapcenter · netapp/storagegrid · tenable/log correlation engine · tenable/nessus · tenable/nessus network monitor · tenable/tenable.sc · fedoraproject/fedora · mcafee/web gateway · mcafee/web gateway cloud service · checkpoint/quantum security management firmware · +40 more
Source
openssl-security@openssl.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.