cbcvebase.
CVE-2021-3618
published 2022-03-23

CVE-2021-3618: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates…

PriorityP345high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
2.04%
78.9th percentile
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiannginx< nginx 1.20.2-2 (bookworm)nginx 1.20.2-2 (bookworm)
debiansendmail< nginx 1.20.2-2 (bookworm)nginx 1.20.2-2 (bookworm)
debianvsftpd< nginx 1.20.2-2 (bookworm)nginx 1.20.2-2 (bookworm)
f5nginx< 1.21.01.21.0
f5nginx>= 0 < 1.18.0-6.1+deb11u21.18.0-6.1+deb11u2
f5nginx>= 0 < 1.20.2-21.20.2-2
f5nginx>= 0 < 1.20.2-21.20.2-2
f5nginx>= 0 < 1.20.2-21.20.2-2
f5nginx>= 0 < 1.14.0-0ubuntu1.101.14.0-0ubuntu1.10
f5nginx>= 0 < 1.18.0-0ubuntu1.31.18.0-0ubuntu1.3
f5nginx>= 0 < 1.18.0-6ubuntu14.11.18.0-6ubuntu14.1
f5nginx>= 0 < 1.10.3-0ubuntu0.16.04.5+esm31.10.3-0ubuntu0.16.04.5+esm3
f5nginx>= 0 < 1.10.3-0ubuntu0.16.04.5+esm41.10.3-0ubuntu0.16.04.5+esm4
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_nginx_1.20.2-2_on_cbl_mariner_2.0
msrccbl2_sendmail_8.15.2-46_on_cbl_mariner_2.0
msrccbl2_vsftpd_3.0.5-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_nginx_1.20.1-3_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.