Cryptographic issues in OpenSSL - CVE-2021-23839

 

Cryptographic issues in OpenSSL - CVE-2021-23839

Published: February 17, 2021 / Updated: October 2, 2024


Vulnerability identifier: #VU50744
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23839
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a MitM attack.

The vulnerability exists due to a faulty implementation of the padding check when server is configured to support SSLv2 protocol. A remote attacker can perform a MitM attack and force the server to use less secure protocols.


Affected software

OpenSSL
IBM Security Verify Bridge
IBM Rational Build Forge
InfoSphere Master Data Management
IBM MaaS360 Cloud Extender Agent
IBM Aspera Orchestrator
IBM Safer Payments
Engineering Workflow Management
IBM Security Verify Gateway
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
IBM Aspera Shares
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
IBM Aspera Console
IBM VIOS
IBM AIX
Junos OS
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
SINEC INS
IBM MaaS360 VPN Module
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
Engineering Lifecycle Management
Dell EMC VxRail Appliance
IBM Cognos Analytics

How to mitigate CVE-2021-23839

Install updates from vendor's website.

OpenSSL - update to 1.0.2y
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.24
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 18.4R2-S10, 19.2R1-S9, 19.2R3-S5, 19.3R3-S5, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S2, 20.4R3-S1, 21.1R3-S1, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
SINEC INS - update to 1.0 SP2
IBM Aspera Shares - update to 1.9.15
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM Aspera Console - update to 3.4.2
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Aspera Faspex for Linux - update to 4.4.2
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Safer Payments - addressed in versions 5.7.0.13, 6.0.0.10, 6.1.0.08, 6.2.1.03
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Dell EMC VxRail Appliance - update to 7.0.240
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2

External References

Related Security Bulletins