cbcvebase.
CVE-2021-23840
published 2021-02-16

CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the…

PriorityP358high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
50.73%
98.8th percentile
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianopenssl< openssl 1.1.1j-1 (bookworm)openssl 1.1.1j-1 (bookworm)
fujitsum10-1_firmware< xcp2410xcp2410
fujitsum10-1_firmware< xcp3110xcp3110
fujitsum10-4_firmware< xcp2410xcp2410
fujitsum10-4_firmware< xcp3110xcp3110
fujitsum10-4s_firmware< xcp2410xcp2410
fujitsum10-4s_firmware< xcp3110xcp3110
fujitsum12-1_firmware< xcp2410xcp2410
fujitsum12-1_firmware< xcp3110xcp3110
fujitsum12-2_firmware< xcp2410xcp2410
fujitsum12-2_firmware< xcp3110xcp3110
fujitsum12-2s_firmware< xcp2410xcp2410
fujitsum12-2s_firmware< xcp3110xcp3110
mcafeeepolicy_orchestrator< 5.10.05.10.0
mcafeeepolicy_orchestrator
msrcazl3_shim-unsigned-aarch64_15.8-5_on_azure_linux_3.0
msrcazl3_shim-unsigned-x64_1.1.1-1_on_azure_linux_3.0
msrcazl3_shim-unsigned-x64_15.8-5_on_azure_linux_3.0
nodejsnode.js
nodejsnode.js10.0.0 – 10.12.0
nodejsnode.js>= 10.13.0 < 10.24.010.24.0
nodejsnode.js12.0.0 – 12.12.0
nodejsnode.js>= 12.13.0 < 12.21.012.21.0
nodejsnode.js14.0.0 – 14.14.0

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for integer overflow conditions in OpenSSL EVP cipher update functions (EVP_CipherUpdate, EVP_EncryptUpdate, EVP_DecryptUpdate) where the return value is 1 (success) but the output length value is negative — this is the characteristic symptom of exploitation.
  • Alert on abnormal spikes in TLS handshake errors and repeated application crashes during certificate validation, which may indicate active exploitation attempts against vulnerable OpenSSL deployments.
  • Configure SIEM detection rules to flag anomalies in OpenSSL processing functions, particularly around X.509 certificate handling events that precede crashes.
  • Use EDR/host-based tools to identify irregular memory or certificate parsing activity associated with OpenSSL, as the vulnerability can be triggered via malformed X.509 certificates submitted during TLS handshakes.
  • For ICS/OT environments, monitor network traffic to MELSOFT GT OPC UA Client (versions 1.00A–1.02C) and GT SoftGOT2000 (versions 1.215Z–1.270G) for specially crafted messages that could trigger the integer overflow DoS condition.
  • ·The vulnerability affects OpenSSL versions 1.1.1i and below (fixed in 1.1.1j) and OpenSSL 1.0.2x and below (fixed in 1.0.2y for premium support customers). Deployments still running these versions are exploitable remotely with low attack complexity over TLS.
  • ·The vulnerability is exploitable remotely with no authentication required and low attack complexity (CVSS AV:N/AC:L/PR:N/UI:N), making unpatched internet-facing OpenSSL services high-priority targets.
  • ·python-cryptography package before version 3.3.2 is also affected as a downstream consumer of the vulnerable OpenSSL functions; Red Hat notes several product lines will not receive fixes.
  • ·No known public exploits specifically targeted the ICS products (MELSOFT GT OPC UA Client / GT SoftGOT2000) at the time of the CISA advisory, but the attack surface is network-accessible.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat9.1CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.