cbcvebase.
CVE-2021-3446
published 2021-03-25

CVE-2021-3446: A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned…

PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.15%
4.6th percentile
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlibtpms< libtpms 0.8.2-1 (bookworm)libtpms 0.8.2-1 (bookworm)
fedoraprojectfedora
libtpms_projectlibtpms< 0.8.20.8.2
libtpms_projectlibtpms
libtpms_projectlibtpms>= 0 < 0.8.2-10.8.2-1
libtpms_projectlibtpms>= 0 < 0.8.2-10.8.2-1
libtpms_projectlibtpms>= 0 < 0.8.2-10.8.2-1
redhatenterprise_linux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.