CVE-2021-3449

MEDIUMCVSS 5.9/10EPSS 63.54%

Last modified

CVE-2021-3449 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. EPSS estimates a 63.54% chance of exploitation in the next 30 days.

Description

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
63.54%

99.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
OpensslOpenssl>= 1.1.1, < 1.1.1k
DebianDebian Linux9.0
DebianDebian Linux10.0
FreebsdFreebsd12.2
NetappActive Iq Unified ManagerAll versions
NetappCloud Volumes Ontap MediatorAll versions
NetappE-Series Performance AnalyzerAll versions
NetappOncommand InsightAll versions
NetappOncommand Workflow AutomationAll versions
NetappOntap Select Deploy Administration UtilityAll versions
NetappSantricity Smi-S ProviderAll versions
NetappSnapcenterAll versions
NetappStoragegridAll versions
TenableLog Correlation Engine< 6.0.9
TenableNessus<= 8.13.1
TenableNessus Network Monitor5.11.0
TenableNessus Network Monitor5.11.1
TenableNessus Network Monitor5.12.0
TenableNessus Network Monitor5.12.1
TenableNessus Network Monitor5.13.0
TenableTenable.Sc>= 5.13.0, <= 5.17.0
FedoraprojectFedora34
McafeeWeb Gateway8.2.19
McafeeWeb Gateway9.2.10
McafeeWeb Gateway10.1.1
McafeeWeb Gateway Cloud Service8.2.19
McafeeWeb Gateway Cloud Service9.2.10
McafeeWeb Gateway Cloud Service10.1.1
CheckpointQuantum Security Management Firmwarer80.40
CheckpointQuantum Security Management Firmwarer81
CheckpointMulti-Domain Management Firmwarer80.40
CheckpointMulti-Domain Management Firmwarer81
CheckpointQuantum Security Gateway Firmwarer80.40
CheckpointQuantum Security Gateway Firmwarer81
OracleCommunications Communications Policy Management12.6.0.0.0
OracleEnterprise Manager For Storage Management13.4.0.0
OracleEssbase21.2
OracleGraalvm19.3.5
OracleGraalvm20.3.1.2
OracleGraalvm21.0.0.2
OracleJd Edwards Enterpriseone Tools< 9.2.6.0
OracleJd Edwards World Securitya9.4
OracleMysql Connectors<= 8.0.23
OracleMysql Server<= 5.7.33
OracleMysql Server>= 8.0.15, <= 8.0.23
OracleMysql Workbench<= 8.0.23
OraclePeoplesoft Enterprise Peopletools8.57
OraclePeoplesoft Enterprise Peopletools8.58
OraclePeoplesoft Enterprise Peopletools8.59
OraclePrimavera Unifier>= 17.7, <= 17.12

Showing 50 of 135 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3449?
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
How severe is CVE-2021-3449?
CVE-2021-3449 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 63.54% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3449?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3449?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST