CVE-2021-22946
published 2021-09-29CVE-2021-22946: A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
4.22%
89.9th percentile
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| debian | curl | < curl 7.79.1-1 (bookworm) | curl 7.79.1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u2 | 7.74.0-1.3+deb11u2 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.16 | 7.58.0-2ubuntu3.16 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.15 | 7.58.0-2ubuntu3.15 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.7 | 7.68.0-1ubuntu2.7 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm8 | 7.35.0-1ubuntu2.20+esm8 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm9 | 7.35.0-1ubuntu2.20+esm9 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm1 | 7.47.0-1ubuntu2.19+esm1 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm2 | 7.47.0-1ubuntu2.19+esm2 |
| haxx | curl | >= 7.20.0 < 7.79.0 | 7.79.0 |
| https | github.com_curl_curl | — | — |
| msrc | cbl2_curl_7.82.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_curl_7.76.0-6_on_cbl_mariner_1.0 | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROX
cisa_ics·2023-07-13
Siemens RUGGEDCOM ROX
ICS Advisory
##
Siemens RUGGEDCOM ROX
Release DateJuly 13, 2023
Alert CodeICSA-23-194-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM ROX
- Vulnerabilities: Cleartext Transmission of Sensitive Information, Command Injection, Improper Authentication, Classic Buffer Overflow, Uncontrolled Resource Consumption, Improper Certificate Validation, Cross-Site Request Forgery (CSRF), Improper Input Validation, Incorrect Default Permissions, Cross-site Scripting, Inadequate Encryption Strength, Use of a Broken or Risky Cryptographic Algorithm.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to send a malformed HTTP packet c
Oracle
Oracle Oracle Essbase Risk Matrix: Build (cURL) — CVE-2021-22946
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle Essbase Risk Matrix: Build (cURL) — CVE-2021-22946
Oracle Oracle Essbase Risk Matrix: Build (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (cURL) — CVE-2021-22946
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (cURL) — CVE-2021-22946
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: CNC BSF (cURL) — CVE-2021-22946
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle Communications Risk Matrix: CNC BSF (cURL) — CVE-2021-22946
Oracle Oracle Communications Risk Matrix: CNC BSF (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Apple
CVE-2021-22946: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 7.5
CVE-2021-22946 [HIGH] CVE-2021-22946: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2021-22946
Component: CVE-2021-22946
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Compiling (cURL) — CVE-2021-22946
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-22946 [HIGH] Oracle Oracle MySQL Risk Matrix: Server: Compiling (cURL) — CVE-2021-22946
Oracle Oracle MySQL Risk Matrix: Server: Compiling (cURL) vulnerability
CVE: CVE-2021-22946
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-09-21·CVSS 9.1
[CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: USN-5079-1 introduced a regression in curl.
USN-5079-1 fixed vulnerabilities in curl. One of the fixes introduced a
regression on Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered
Ubuntu
curl regression
vendor_ubuntu·2021-09-21·CVSS 7.5
CVE-2021-22946 [HIGH] curl regression
Title: curl regression
Summary: USN-5079-2 introduced a regression in curl.
USN-5079-2 fixed vulnerabilities in curl. One of the fixes introduced a
regression. This update fixes the problem.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-09-15·CVSS 7.5
CVE-2021-22946 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-5079-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-09-15·CVSS 9.1
CVE-2021-22947 [CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
Instructions: In ge
Red Hat
curl: Requirement to use TLS not properly enforced for IMAP, POP3, and FTP protocols
vendor_redhat·2021-09-15·CVSS 7.5
CVE-2021-22946 [HIGH] CWE-319 curl: Requirement to use TLS not properly enforced for IMAP, POP3, and FTP protocols
curl: Requirement to use TLS not properly enforced for IMAP, POP3, and FTP protocols
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
A flaw was found in curl. This flaw lies in the --ssl-reqd option or related settings in libcurl. Users specify this flag to upgrade to TLS when communicating wit
Microsoft
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL
vendor_msrc·2021-09-14·CVSS 7.5
CVE-2021-22946 [HIGH] CWE-319 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL
A user can tell curl >= 7.20.0 and Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-u
Debian
CVE-2021-22946: curl - A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to ...
vendor_debian·2021·CVSS 7.5
CVE-2021-22946 [HIGH] CVE-2021-22946: curl - A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to ...
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
Scope: local
bookworm: resolved (fixed in 7.79.1-1)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u2)
forky: resolved (fixed in 7.79.1-1)
sid: resolved (fixed in 7.79.1-1)
trixie: resolved (fixed in 7.79.1-1)
GHSA
GHSA-3cmq-42w4-c529: A user can tell curl >= 7
ghsa_unreviewed·2022-05-24
CVE-2021-22946 [HIGH] CWE-319 GHSA-3cmq-42w4-c529: A user can tell curl >= 7
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
OSV
CVE-2021-22946: A user can tell curl >= 7
osv·2021-09-29·CVSS 7.5
CVE-2021-22946 [HIGH] CVE-2021-22946: A user can tell curl >= 7
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
OSV
curl vulnerabilities
osv·2021-09-21·CVSS 9.1
CVE-2021-22945 [CRITICAL] curl vulnerabilities
curl vulnerabilities
USN-5079-1 fixed vulnerabilities in curl. One of the fixes introduced a
regression on Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before START
OSV
curl regression
osv·2021-09-21·CVSS 7.5
CVE-2021-22946 [HIGH] curl regression
curl regression
USN-5079-2 fixed vulnerabilities in curl. One of the fixes introduced a
regression. This update fixes the problem.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
OSV
curl vulnerabilities
osv·2021-09-15·CVSS 9.1
CVE-2021-22945 [CRITICAL] curl vulnerabilities
curl vulnerabilities
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
OSV
curl vulnerabilities
osv·2021-09-15·CVSS 7.5
CVE-2021-22946 [HIGH] curl vulnerabilities
curl vulnerabilities
USN-5079-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2022/Mar/29https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1334111https://lists.debian.org/debian-lts-announce/2021/09/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20211029-0003/https://security.netapp.com/advisory/ntap-20220121-0008/https://support.apple.com/kb/HT213183https://www.debian.org/security/2022/dsa-5197https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://seclists.org/fulldisclosure/2022/Mar/29https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1334111https://lists.debian.org/debian-lts-announce/2021/09/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20211029-0003/https://security.netapp.com/advisory/ntap-20220121-0008/https://support.apple.com/kb/HT213183https://www.debian.org/security/2022/dsa-5197https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-09-29
Published