CVE-2021-3580
published 2021-08-05CVE-2021-3580: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nettle | < nettle 3.7.3-1 (bookworm) | nettle 3.7.3-1 (bookworm) |
| msrc | cbl2_nettle_3.7.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_nettle_3.7.3-1_on_cbl_mariner_1.0 | — | — |
| nettle_project | nettle | < 3.7.3 | 3.7.3 |
| nettle_project | nettle | — | — |
| nettle_project | nettle | >= 0 < 3.7.3-1 | 3.7.3-1 |
| nettle_project | nettle | >= 0 < 3.7.3-1 | 3.7.3-1 |
| nettle_project | nettle | >= 0 < 3.7.3-1 | 3.7.3-1 |
| nettle_project | nettle | >= 0 < 3.7.3-1 | 3.7.3-1 |
| nettle_project | nettle | >= 0 < 3.4.1-0ubuntu0.18.04.1 | 3.4.1-0ubuntu0.18.04.1 |
| nettle_project | nettle | >= 0 < 3.5.1+really3.5.1-2ubuntu0.2 | 3.5.1+really3.5.1-2ubuntu0.2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Microsoft
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and
vendor_msrc·2021-08-10·CVSS 7.5
CVE-2021-3580 [HIGH] CWE-20 A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified,
Ubuntu
Nettle vulnerabilities
vendor_ubuntu·2021-06-17·CVSS 5.7
CVE-2018-16869 [MEDIUM] Nettle vulnerabilities
Title: Nettle vulnerabilities
Summary: Several security issues were fixed in Nettle.
It was discovered that Nettle incorrectly handled RSA decryption. A remote
attacker could possibly use this issue to cause Nettle to crash, resulting
in a denial of service. (CVE-2021-3580)
It was discovered that Nettle incorrectly handled certain padding oracles.
A remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-16869)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nettle: Remote crash in RSA decryption via manipulated ciphertext
vendor_redhat·2021-06-07·CVSS 7.5
CVE-2021-3580 [HIGH] CWE-20 nettle: Remote crash in RSA decryption via manipulated ciphertext
nettle: Remote crash in RSA decryption via manipulated ciphertext
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
A flaw was found in nettle in the way its RSA decryption functions handle specially crafted ciphertext. This flaw allows an attacker to provide a manipulated ciphertext, leading to an application crash and a denial of service.
Mitigation: As per upstream: For applications that want to support older versions of nettle, the bug can be worked around by adding a check that the RSA ciphertext is in the range 0 < ciphertext < n, before attempting to decrypt it.
Package: nettle (Red Hat Enterprise Linux 7) - Wil
Debian
CVE-2021-3580: nettle - A flaw was found in the way nettle's RSA decryption functions handled specially ...
vendor_debian·2021·CVSS 7.5
CVE-2021-3580 [HIGH] CVE-2021-3580: nettle - A flaw was found in the way nettle's RSA decryption functions handled specially ...
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
Scope: local
bookworm: resolved (fixed in 3.7.3-1)
bullseye: resolved (fixed in 3.7.3-1)
forky: resolved (fixed in 3.7.3-1)
sid: resolved (fixed in 3.7.3-1)
trixie: resolved (fixed in 3.7.3-1)
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·2020-10-21·CVSS 6.1
CVE-2020-3580 [MEDIUM] CWE-79 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021: Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited.
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device.
The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuadi
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3583 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3583: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3581 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3581: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3580 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3580: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3582 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
CVE-2020-3582: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
Update June 28, 2021 : Cisco has become aware that public exploit code exists for CVE-2020-3580, and this vulnerability is being actively exploited. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabiliti
GHSA
GHSA-52fp-4722-wcjw: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext
ghsa_unreviewed·2022-05-24
CVE-2021-3580 [HIGH] CWE-20 GHSA-52fp-4722-wcjw: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
OSV
CVE-2021-3580: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext
osv·2021-08-05·CVSS 7.5
CVE-2021-3580 [HIGH] CVE-2021-3580: A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
OSV
nettle vulnerabilities
osv·2021-06-17·CVSS 5.7
CVE-2021-3580 [MEDIUM] nettle vulnerabilities
nettle vulnerabilities
It was discovered that Nettle incorrectly handled RSA decryption. A remote
attacker could possibly use this issue to cause Nettle to crash, resulting
in a denial of service. (CVE-2021-3580)
It was discovered that Nettle incorrectly handled certain padding oracles.
A remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-16869)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1967983https://lists.debian.org/debian-lts-announce/2021/09/msg00008.htmlhttps://security.gentoo.org/glsa/202401-24https://security.netapp.com/advisory/ntap-20211104-0006/https://bugzilla.redhat.com/show_bug.cgi?id=1967983https://lists.debian.org/debian-lts-announce/2021/09/msg00008.htmlhttps://security.gentoo.org/glsa/202401-24https://security.netapp.com/advisory/ntap-20211104-0006/
2021-08-05
Published