CVE-2021-3618
published 2022-03-23CVE-2021-3618: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates…
PriorityP345high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
2.04%
78.9th percentile
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.20.2-2 (bookworm) | nginx 1.20.2-2 (bookworm) |
| debian | sendmail | < nginx 1.20.2-2 (bookworm) | nginx 1.20.2-2 (bookworm) |
| debian | vsftpd | < nginx 1.20.2-2 (bookworm) | nginx 1.20.2-2 (bookworm) |
| f5 | nginx | < 1.21.0 | 1.21.0 |
| f5 | nginx | >= 0 < 1.18.0-6.1+deb11u2 | 1.18.0-6.1+deb11u2 |
| f5 | nginx | >= 0 < 1.20.2-2 | 1.20.2-2 |
| f5 | nginx | >= 0 < 1.20.2-2 | 1.20.2-2 |
| f5 | nginx | >= 0 < 1.20.2-2 | 1.20.2-2 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.10 | 1.14.0-0ubuntu1.10 |
| f5 | nginx | >= 0 < 1.18.0-0ubuntu1.3 | 1.18.0-0ubuntu1.3 |
| f5 | nginx | >= 0 < 1.18.0-6ubuntu14.1 | 1.18.0-6ubuntu14.1 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm3 | 1.10.3-0ubuntu0.16.04.5+esm3 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm4 | 1.10.3-0ubuntu0.16.04.5+esm4 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_nginx_1.20.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_sendmail_8.15.2-46_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_vsftpd_3.0.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_nginx_1.20.1-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Ubuntu
vsftpd vulnerability
vendor_ubuntu·2023-09-18
CVE-2021-3618 vsftpd vulnerability
Title: vsftpd vulnerability
Summary: vsftpd could allow unintended access to network services.
It was discovered that vsftpd was vulnerable to the ALPACA TLS protocol
content confusion attack. A remote attacker could possibly use this issue
to redirect traffic from one subdomain to another.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Ubuntu
nginx vulnerability
vendor_ubuntu·2022-10-07·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerability
Title: nginx vulnerability
Summary: A security issue was fixed in nginx's lua module.
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certifi
Ubuntu
nginx vulnerability
vendor_ubuntu·2022-04-28·CVSS 7.5
CVE-2021-3618 [HIGH] nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to redirect network traffic.
USN-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption pr
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2022-04-12·CVSS 7.5
CVE-2020-36309 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618
Microsoft
ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates
vendor_msrc·2022-03-08·CVSS 7.4
CVE-2021-3618 [HIGH] CWE-295 ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates
ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to da
Red Hat
ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
vendor_redhat·2021-06-09·CVSS 7.4
CVE-2021-3618 [HIGH] CWE-295 ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such
Debian
CVE-2021-3618: nginx - ALPACA is an application layer protocol content confusion attack, exploiting TLS...
vendor_debian·2021·CVSS 7.4
CVE-2021-3618 [HIGH] CVE-2021-3618: nginx - ALPACA is an application layer protocol content confusion attack, exploiting TLS...
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Scope: local
bookworm: resolved (fixed in 1.20.2-2)
bullseye: resolved (fixed in 1.18.0-6.1+deb11u2)
forky: resolved (fixed in 1.20.2-2)
sid: resolved (fixed in 1.20.2-2)
trixie: resolved (fixed in 1.20.2-2)
OSV
nginx vulnerability
osv·2022-10-07·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerability
nginx vulnerability
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker wer
OSV
nginx vulnerability
osv·2022-04-28·CVSS 7.5
CVE-2021-3618 [HIGH] nginx vulnerability
nginx vulnerability
USN-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communica
OSV
nginx vulnerabilities
osv·2022-04-12·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618)
GHSA
GHSA-r9r5-jxp7-whr4: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certifi
ghsa_unreviewed·2022-03-24
CVE-2021-3618 [HIGH] CWE-295 GHSA-r9r5-jxp7-whr4: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certifi
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
OSV
CVE-2021-3618: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certifi
osv·2022-03-23·CVSS 7.4
CVE-2021-3618 [HIGH] CVE-2021-3618: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certifi
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14242 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-14242 [CRITICAL] CVE-2025-14242 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14242 :
vsftpd vulnerability analysis and mitigation
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
vsftpd
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 34.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
vsftpd-debuginfo
vsftpd-debugsource
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Jan 20, 2026
AlmaLinux 9 Severi
Bugzilla
CVE-2021-47185 kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
bugzilla·2024-04-11·CVSS 4.4
CVE-2021-47185 [MEDIUM] CVE-2021-47185 kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
CVE-2021-47185 kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
In the Linux kernel, the following vulnerability has been resolved:
tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
The Linux kernel CVE team has assigned CVE-2021-47185 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041033-CVE-2021-47185-c363@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE
Bugzilla
CVE-2021-47171 kernel: net: usb: fix memory leak in smsc75xx_bind
bugzilla·2024-03-25·CVSS 5.5
CVE-2021-47171 [MEDIUM] CVE-2021-47171 kernel: net: usb: fix memory leak in smsc75xx_bind
CVE-2021-47171 kernel: net: usb: fix memory leak in smsc75xx_bind
In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
The Linux kernel CVE team has assigned CVE-2021-47171 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024032536-CVE-2021-47171-f223@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47171 is: CHECK Maybe valid.
Bugzilla
CVE-2021-47153 kernel: i2c: i801: Don't generate an interrupt on bus reset
bugzilla·2024-03-25·CVSS 7.1
CVE-2021-47153 [HIGH] CVE-2021-47153 kernel: i2c: i801: Don't generate an interrupt on bus reset
CVE-2021-47153 kernel: i2c: i801: Don't generate an interrupt on bus reset
In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: Don't generate an interrupt on bus reset
The Linux kernel CVE team has assigned CVE-2021-47153 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024032501-CVE-2021-47153-8c75@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47153 is:
Bugzilla
CVE-2021-47118 kernel: pid: take a reference when initializing `cad_pid`
bugzilla·2024-03-16·CVSS 7.8
CVE-2021-47118 [HIGH] CVE-2021-47118 kernel: pid: take a reference when initializing `cad_pid`
CVE-2021-47118 kernel: pid: take a reference when initializing `cad_pid`
In the Linux kernel, the following vulnerability has been resolved:
pid: take a reference when initializing `cad_pid`
The Linux kernel CVE team has assigned CVE-2021-47118 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024031509-CVE-2021-47118-faf2@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2269858]
---
This was fixed for Fedora with the 5.12.10 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:
Bugzilla
CVE-2021-47055 kernel: mtd: require write permissions for locking and badblock ioctls
bugzilla·2024-03-01·CVSS 5.5
CVE-2021-47055 [MEDIUM] CVE-2021-47055 kernel: mtd: require write permissions for locking and badblock ioctls
CVE-2021-47055 kernel: mtd: require write permissions for locking and badblock ioctls
In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
The Linux kernel CVE team has assigned CVE-2021-47055 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022950-CVE-2021-47055-6927@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267186]
---
This was fixed for Fedora with the 5.12.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterpris
Bugzilla
CVE-2021-46934 kernel: i2c: validate user data in compat ioctl
bugzilla·2024-02-27·CVSS 3.3
CVE-2021-46934 [LOW] CVE-2021-46934 kernel: i2c: validate user data in compat ioctl
CVE-2021-46934 kernel: i2c: validate user data in compat ioctl
In the Linux kernel, the following vulnerability has been resolved:
i2c: validate user data in compat ioctl
The Linux kernel CVE team has assigned CVE-2021-46934 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022750-CVE-2021-46934-79c8@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2266447]
---
This was fixed for Fedora with the 5.15.13 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.
Bugzilla
CVE-2021-3618 ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
bugzilla·2021-06-24·CVSS 7.4
CVE-2021-3618 [HIGH] CVE-2021-3618 ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
CVE-2021-3618 ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
As per the researchers:
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. Attackers can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Discussion:
Analysis:
The generic attack requires a MitM attacker that can intercept and divert the victim's traffic at the TCP/IP layer.The attacker needs to have some way of inter
arXiv
CAI: An Open, Bug Bounty-Ready Cybersecurity AI
arxiv_fulltext·2025-04-09
CAI: An Open, Bug Bounty-Ready Cybersecurity AI
-1em
## Abstract
By 2028 most cybersecurity actions will be autonomous, with humans teleoperating. We present the first classification of autonomy levels in cybersecurity and introduce Cybersecurity AI (CAI), an open-source framework that democratizes advanced security testing through specialized AI agents. Through rigorous empirical evaluation, we demonstrate that CAI consistently outperforms state-of-the-art results in CTF benchmarks, solving challenges across diverse categories with significantly greater efficiency --up to 3,600 faster than humans in specific tasks and averaging 11 faster overall. CAI achieved first place among AI teams and secured a top-20 position worldwide in the "AI vs Human" CTF live Challenge, earning a monetary reward of \750. Based on our results, we argue aga
2022-03-23
Published