CVE-2021-4160

Severity
5.9MEDIUM
EPSS
0.3%
top 46.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateApr 15

Description

There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficu

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages9 packages

NVDopenssl/openssl1.1.11.1.1m+2
Debianopenssl< 1.1.1k-1+deb11u2+3
CVEListV5openssl/opensslFixed in OpenSSL 1.0.2zc-dev (Affected 1.0.2-1.0.2zb), Fixed in OpenSSL 1.1.1m (Affected 1.1.1-1.1.1l), Fixed in OpenSSL 3.0.1 (Affected 3.0.0)+2
NVDsiemens/sinec_ins< 1.0+1

Also affects: Debian Linux 10.0, 11.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-ph2x-8239-7xc7: There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure2022-02-08
CVEList
BN_mod_exp may produce incorrect results on MIPS2022-01-28
OSV
CVE-2021-4160: There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure2022-01-28

📋Vendor Advisories

4
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Security (OpenSSL) — CVE-2021-41602022-04-15
Red Hat
openssl: Carry propagation bug in the MIPS32 and MIPS64 squaring procedure2022-01-28
Microsoft
BN_mod_exp may produce incorrect results on MIPS2022-01-11
Debian
CVE-2021-4160: openssl - There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Ma...2021
CVE-2021-4160 (MEDIUM CVSS 5.9) | There is a carry propagation bug in | cvebase.io