Cryptographic issues in OpenSSL - CVE-2021-23839
Published: February 17, 2021 / Updated: October 2, 2024
Vulnerability identifier: #VU50744
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23839
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a MitM attack.
The vulnerability exists due to a faulty implementation of the padding check when server is configured to support SSLv2 protocol. A remote attacker can perform a MitM attack and force the server to use less secure protocols.
Affected software
OpenSSL
IBM Security Verify Bridge
IBM Rational Build Forge
InfoSphere Master Data Management
IBM MaaS360 Cloud Extender Agent
IBM Aspera Orchestrator
IBM Safer Payments
Engineering Workflow Management
IBM Security Verify Gateway
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
IBM Aspera Shares
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
IBM Aspera Console
IBM VIOS
IBM AIX
Junos OS
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
SINEC INS
IBM MaaS360 VPN Module
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
Engineering Lifecycle Management
Dell EMC VxRail Appliance
IBM Cognos Analytics
IBM Security Verify Bridge
IBM Rational Build Forge
InfoSphere Master Data Management
IBM MaaS360 Cloud Extender Agent
IBM Aspera Orchestrator
IBM Safer Payments
Engineering Workflow Management
IBM Security Verify Gateway
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
IBM Aspera Shares
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
IBM Aspera Console
IBM VIOS
IBM AIX
Junos OS
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
SINEC INS
IBM MaaS360 VPN Module
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
Engineering Lifecycle Management
Dell EMC VxRail Appliance
IBM Cognos Analytics
How to mitigate CVE-2021-23839
Install updates from vendor's website.
OpenSSL - update to 1.0.2y
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.24
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 18.4R2-S10, 19.2R1-S9, 19.2R3-S5, 19.3R3-S5, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S2, 20.4R3-S1, 21.1R3-S1, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
SINEC INS - update to 1.0 SP2
IBM Aspera Shares - update to 1.9.15
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM Aspera Console - update to 3.4.2
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Aspera Faspex for Linux - update to 4.4.2
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Safer Payments - addressed in versions 5.7.0.13, 6.0.0.10, 6.1.0.08, 6.2.1.03
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Dell EMC VxRail Appliance - update to 7.0.240
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.24
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 18.4R2-S10, 19.2R1-S9, 19.2R3-S5, 19.3R3-S5, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S2, 20.4R3-S1, 21.1R3-S1, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
SINEC INS - update to 1.0 SP2
IBM Aspera Shares - update to 1.9.15
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM Aspera Console - update to 3.4.2
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Aspera Faspex for Linux - update to 4.4.2
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Safer Payments - addressed in versions 5.7.0.13, 6.0.0.10, 6.1.0.08, 6.2.1.03
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Dell EMC VxRail Appliance - update to 7.0.240
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- IBM AIX update for OpenSSL
- IBM VIOS update for OpenSSL
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Junos OS update for OpenSSL
- Multiple vulnerabilities in IBM InfoSphere Master Data Management
- Multiple vulnerabilities in IBM Aspera Console and Aspera Shares
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in IBM Security Verify products
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender and Modules
- Multiple vulnerabilities in IBM Security Verify Bridge
- Multiple vulnerabilities in IBM Aspera Faspex
- Multiple vulnerabilities in IBM Aspera Orchestrator
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in Dell ThinOS