cbcvebase.
CVE-2021-3449
published 2021-03-25

CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the…

PriorityP349medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
62.91%
99.1th percentile
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Affected

107 ranges· showing 25
VendorProductVersion rangeFixed in
checkpointmulti-domain_management_firmware
checkpointmulti-domain_management_firmware
checkpointquantum_security_gateway_firmware
checkpointquantum_security_gateway_firmware
checkpointquantum_security_management_firmware
checkpointquantum_security_management_firmware
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.1.1k-1 (bookworm)openssl 1.1.1k-1 (bookworm)
fedoraprojectfedora
freebsdfreebsd
mcafeeweb_gateway
mcafeeweb_gateway
mcafeeweb_gateway
mcafeeweb_gateway_cloud_service
mcafeeweb_gateway_cloud_service
mcafeeweb_gateway_cloud_service
msrcmicrosoft_visual_studio_2017_version_15.9
msrcmicrosoft_visual_studio_2019_version_16.11
msrcmicrosoft_visual_studio_2019_version_16.4
msrcmicrosoft_visual_studio_2019_version_16.7
msrcmicrosoft_visual_studio_2019_version_16.9
nodejsnode.js10.0.0 – 10.12.0
nodejsnode.js10.13.0 – 10.24.0
nodejsnode.js12.0.0 – 12.12.0

Detection & IOCsextracted from sources · hover to see the quote

  • Target TLS servers with TLSv1.2 and renegotiation enabled (default config). The attack requires sending a renegotiation ClientHello that omits the signature_algorithms extension (present in the initial ClientHello) but includes a signature_algorithms_cert extension, triggering a NULL pointer dereference crash.
  • A server is only vulnerable if TLSv1.2 AND renegotiation are both enabled. Disabling either TLSv1.2 (TLSv1.3 is unaffected) or disabling renegotiation on the TLS server mitigates the issue.
  • OpenSSL TLS clients are NOT impacted; detection/monitoring should focus exclusively on server-side TLS traffic for anomalous renegotiation handshakes.
  • ·Only OpenSSL versions 1.1.1 through 1.1.1j are affected. OpenSSL 1.0.2 is NOT impacted. The fix is present in OpenSSL 1.1.1k and later.
  • ·The vulnerability is exploitable only when both TLSv1.2 and renegotiation are enabled, which is the default OpenSSL server configuration — meaning most unpatched servers are exposed without any non-default configuration required.

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_oracle7.5MEDIUM
vendor_cisco7.4HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9HIGH
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.