5.9

CVE-2021-3449

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSLOpenSSL Version >= 1.1.1 < 1.1.1k
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
FreebsdFreebsd Version12.2 Update-
FreebsdFreebsd Version12.2 Updatep1
FreebsdFreebsd Version12.2 Updatep2
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappOncommand Insight Version-
NetappSnapcenter Version-
NetappStoragegrid Version-
TenableLog Correlation Engine Version < 6.0.9
TenableNessus Version <= 8.13.1
TenableNessus Network Monitor Version5.11.0
TenableNessus Network Monitor Version5.11.1
TenableNessus Network Monitor Version5.12.0
TenableNessus Network Monitor Version5.12.1
TenableNessus Network Monitor Version5.13.0
TenableTenable.Sc Version >= 5.13.0 <= 5.17.0
FedoraprojectFedora Version34
McafeeWeb Gateway Version8.2.19
McafeeWeb Gateway Version9.2.10
McafeeWeb Gateway Version10.1.1
McafeeWeb Gateway Cloud Service Version8.2.19
McafeeWeb Gateway Cloud Service Version9.2.10
McafeeWeb Gateway Cloud Service Version10.1.1
OracleEssbase Version21.2
OracleGraalvm Version19.3.5 SwEditionenterprise
OracleGraalvm Version20.3.1.2 SwEditionenterprise
OracleGraalvm Version21.0.0.2 SwEditionenterprise
OracleJd Edwards Enterpriseone Tools Version < 9.2.6.0
OracleMysql Connectors Version <= 8.0.23
OracleMysql Server Version <= 5.7.33
OracleMysql Server Version >= 8.0.15 <= 8.0.23
OracleMysql Workbench Version <= 8.0.23
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleSecure Backup Version < 18.1.0.1.0
OracleSecure Global Desktop Version5.6
SonicwallSma100 Firmware Version >= 10.2.0.0 < 10.2.1.0-17sv
   SonicwallSma100 Version-
SonicwallCapture Client Version3.5
SonicwallSonicos Version7.0.1.0
SiemensRuggedcom Rcm1224 Firmware Version >= 6.2
   SiemensRuggedcom Rcm1224 Version-
SiemensScalance M-800 Firmware Version >= 6.2
   SiemensScalance M-800 Version-
SiemensScalance S602 Firmware Version >= 4.1
   SiemensScalance S602 Version-
SiemensScalance S612 Firmware Version >= 4.1
   SiemensScalance S612 Version-
SiemensScalance S615 Firmware Version >= 6.2
   SiemensScalance S615 Version-
SiemensScalance S623 Firmware Version >= 4.1
   SiemensScalance S623 Version-
SiemensScalance S627-2m Firmware Version >= 4.1
   SiemensScalance S627-2m Version-
SiemensScalance Sc-600 Firmware Version >= 2.0
   SiemensScalance Sc-600 Version-
SiemensScalance W700 Firmware Version >= 6.5
   SiemensScalance W700 Version-
SiemensScalance W1700 Firmware Version >= 2.0
   SiemensScalance W1700 Version-
SiemensScalance Xb-200 Firmware Version < 4.3
   SiemensScalance Xb-200 Version-
SiemensScalance Xc-200 Firmware Version < 4.3
   SiemensScalance Xc-200 Version-
SiemensScalance Xf-200ba Firmware Version < 4.3
   SiemensScalance Xf-200ba Version-
SiemensScalance Xm-400 Firmware Version < 6.4
   SiemensScalance Xm-400 Version-
SiemensScalance Xp-200 Firmware Version < 4.3
   SiemensScalance Xp-200 Version-
SiemensScalance Xr-300wg Firmware Version < 4.3
   SiemensScalance Xr-300wg Version-
SiemensScalance Xr524-8c Firmware Version < 6.4
   SiemensScalance Xr524-8c Version-
SiemensScalance Xr526-8c Firmware Version < 6.4
   SiemensScalance Xr526-8c Version-
SiemensScalance Xr528-6m Firmware Version < 6.4
   SiemensScalance Xr528-6m Version-
SiemensScalance Xr552-12 Firmware Version < 6.4
   SiemensScalance Xr552-12 Version-
SiemensSimatic Net Cp 1543-1 Firmware Version >= 2.2 < 3.0
   SiemensSimatic Net Cp 1543-1 Version-
SiemensSimatic Pdm Firmware Version >= 9.1.0.7
   SiemensSimatic Pdm Version-
SiemensTim 1531 Irc Firmware Version >= 2.0 < 2.2
   SiemensTim 1531 Irc Version-
SiemensSimatic Logon Version >= 1.6.0.2
SiemensSimatic Logon Version1.5 Updatesp3_update_1
SiemensSinec Nms Version1.0 Update-
SiemensSinec Nms Version1.0 Updatesp1
SiemensSinec Pni Version-
SiemensSinema Server Version14.0 Update-
SiemensSinema Server Version14.0 Updatesp1
SiemensSinema Server Version14.0 Updatesp2
SiemensSinema Server Version14.0 Updatesp2_update1
SiemensSinema Server Version14.0 Updatesp2_update2
NodejsNode.Js SwEdition- Version >= 10.0.0 <= 10.12.0
NodejsNode.Js SwEditionlts Version >= 10.13.0 <= 10.24.0
NodejsNode.Js SwEdition- Version >= 12.0.0 <= 12.12.0
NodejsNode.Js SwEditionlts Version >= 12.13.0 < 12.22.1
NodejsNode.Js SwEdition- Version >= 14.0.0 <= 14.14.0
NodejsNode.Js SwEditionlts Version >= 14.15.0 < 14.16.1
NodejsNode.Js SwEdition- Version >= 15.0.0 < 15.14.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.18% 0.939
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.