CVE-2021-3449
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 62.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 62.91% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- openssl/openssl · debian/debian linux · freebsd/freebsd · netapp/active iq unified manager · netapp/cloud volumes ontap mediator · netapp/e-series performance analyzer · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/ontap select deploy administration utility · netapp/santricity smi-s provider · netapp/snapcenter · netapp/storagegrid · tenable/log correlation engine · tenable/nessus · tenable/nessus network monitor · tenable/tenable.sc · fedoraproject/fedora · mcafee/web gateway · mcafee/web gateway cloud service · checkpoint/quantum security management firmware · +40 more
- Source
- openssl-security@openssl.org
References
- http://www.openwall.com/lists/oss-security/2021/03/27/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/27/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/28/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/28/4Mailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdfPatch, Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10356Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00029.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.ascThird Party Advisory
- https://security.gentoo.org/glsa/202103-03Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210326-0006/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210513-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJdThird Party Advisory
- https://www.debian.org/security/2021/dsa-4875Third Party Advisory
- https://www.openssl.org/news/secadv/20210325.txtVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlThird Party Advisory
- https://www.tenable.com/security/tns-2021-05Third Party Advisory
- https://www.tenable.com/security/tns-2021-06Third Party Advisory
- https://www.tenable.com/security/tns-2021-09Third Party Advisory
- https://www.tenable.com/security/tns-2021-10Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/27/1Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.