Security features bypass in OpenSSL - CVE-2021-3450
Published: March 25, 2021
Vulnerability identifier: #VU51732
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3450
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in implementation of the X509_V_FLAG_X509_STRICT flag allows an attacker to overwrite a valid CA certificate using any non-CA certificate in the chain. As a result, a remote attacker can perform MitM attack.
Affected software
OpenSSL
Arch Linux
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
Fedora
SonicOS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Module for Web Scripting
FreeBSD
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
IBM Security Verify Bridge
IBM Netcool Agile Service Manager
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Management for Kubernetes
IBM Security Guardium Insights
EasyApache
Tenable Nessus
IBM Integration Bus
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Safer Payments
PowerProtect Data Manager
IBM Security Verify Gateway
Oracle Secure Backup
JBoss Core Services
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
imgbased (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
scap-security-guide (Red Hat package)
isl (Red Hat package)
libmpc (Red Hat package)
openssl11
openssl (Red Hat package)
openssl
boost (Red Hat package)
zip (Red Hat package)
libxcrypt (Red Hat package)
make (Red Hat package)
gcc (Red Hat package)
dyninst (Red Hat package)
nodejs10
nodejs10-docs
npm10
nodejs10-devel
nodejs10-debugsource
nodejs10-debuginfo
nodejs12-docs
npm12
nodejs12-devel
nodejs12-debugsource
nodejs12-debuginfo
nodejs12
tbb (Red Hat package)
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
Red Hat Virtualization
Oracle GraalVM Enterprise Edition
Cloud Pak for Security (CP4S)
Nessus Agent
Enterprise Manager for Storage Management
Red Hat OpenShift Jaeger
SonicWall Capture Client
Red Hat Virtualization Host
Nessus Network Monitor
Oracle Secure Global Desktop
LANTIME Operating System Firmware (LTOS)
MySQL Enterprise Monitor
IBM InfoSphere Information Server
MySQL Connectors
MySQL Workbench
IBM App Connect Enterprise
Visual Studio
PeopleSoft Enterprise PeopleTools
IBM Security Verify Access
SMA 100
Oracle Commerce Guided Search
SINEC INS
JBoss Web Server
Arch Linux
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
Fedora
SonicOS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Module for Web Scripting
FreeBSD
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
IBM Security Verify Bridge
IBM Netcool Agile Service Manager
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Management for Kubernetes
IBM Security Guardium Insights
EasyApache
Tenable Nessus
IBM Integration Bus
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Safer Payments
PowerProtect Data Manager
IBM Security Verify Gateway
Oracle Secure Backup
JBoss Core Services
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
imgbased (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
scap-security-guide (Red Hat package)
isl (Red Hat package)
libmpc (Red Hat package)
openssl11
openssl (Red Hat package)
openssl
boost (Red Hat package)
zip (Red Hat package)
libxcrypt (Red Hat package)
make (Red Hat package)
gcc (Red Hat package)
dyninst (Red Hat package)
nodejs10
nodejs10-docs
npm10
nodejs10-devel
nodejs10-debugsource
nodejs10-debuginfo
nodejs12-docs
npm12
nodejs12-devel
nodejs12-debugsource
nodejs12-debuginfo
nodejs12
tbb (Red Hat package)
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
Red Hat Virtualization
Oracle GraalVM Enterprise Edition
Cloud Pak for Security (CP4S)
Nessus Agent
Enterprise Manager for Storage Management
Red Hat OpenShift Jaeger
SonicWall Capture Client
Red Hat Virtualization Host
Nessus Network Monitor
Oracle Secure Global Desktop
LANTIME Operating System Firmware (LTOS)
MySQL Enterprise Monitor
IBM InfoSphere Information Server
MySQL Connectors
MySQL Workbench
IBM App Connect Enterprise
Visual Studio
PeopleSoft Enterprise PeopleTools
IBM Security Verify Access
SMA 100
Oracle Commerce Guided Search
SINEC INS
JBoss Web Server
How to mitigate CVE-2021-3450
Install updates from vendor's website.
OpenSSL - update to 1.1.1k
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.jbcs.el7
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.14.0
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.jbcs.el7
IBM Netcool Agile Service Manager - update to 1.1.13
imgbased (Red Hat package) - update to 1.2.18-0.1.el8ev
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - update to 1.15.7-14.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.jbcs.el7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.0.10, 2.1.6, 2.2.2
Windows Container Support for Red Hat OpenShift - update to 2.0.1
jbcs-httpd24-mod_md (Red Hat package) - update to 2.0.8-33.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - update to 2.4.37-70.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - update to 2.9.2-60.GA.jbcs.el7
IBM Security Guardium Insights - update to 3.0.1
SonicWall Capture Client - update to 3.6.24
EasyApache - addressed in versions 4 2021-3-31, 4 2021-4-28
redhat-release-virtualization-host (Red Hat package) - update to 4.4.5-4.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.4.5-20210330.0.el8_3
Nessus Network Monitor - update to 5.13.1
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.028, 7.02.003
SonicOS - update to 7.0.1-R1456
MySQL Enterprise Monitor - update to 8.0.24
Nessus Agent - update to 8.2.4
Tenable Nessus - update to 8.13.2
MySQL Connectors - update to 8.0.24
MySQL Workbench - update to 8.0.24
SMA 100 - update to 10.2.1.0-17sv
IBM App Connect Enterprise - update to 11.0.0.13
Oracle Secure Backup - update to 18.1.0.1.0
scap-security-guide (Red Hat package) - update to 0.1.50-1.el8ev
isl (Red Hat package) - update to 0.16.1-6.el8
SINEC INS - update to 1.0.1.1
libmpc (Red Hat package) - update to 1.0.2-9.el8
openssl11 - update to 1.1.1g-3.el7
openssl (Red Hat package) - update to 1.1.1g-15.el8_3
openssl - update to 1.1.1k-1.fc34
boost (Red Hat package) - update to 1.66.0-10.el8
zip (Red Hat package) - update to 3.0-23.el8
JBoss Web Server - addressed in versions 3.1 SP12, 5.4.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
libxcrypt (Red Hat package) - update to 4.1.1-4.el8
make (Red Hat package) - update to 4.2.1-10.el8
IBM Safer Payments - addressed in versions 6.1.0.08, 6.2.1.03
gcc (Red Hat package) - update to 8.3.1-5.1.el8
dyninst (Red Hat package) - update to 10.1.0-4.el8
nodejs10 - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-docs - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
npm10 - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-devel - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-debugsource - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-debuginfo - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs12-docs - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
npm12 - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-devel - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-debugsource - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-debuginfo - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12 - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
PowerProtect Data Manager - update to 19.19.0-15
tbb (Red Hat package) - update to 2018.2-9.el8
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.jbcs.el7
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.14.0
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.jbcs.el7
IBM Netcool Agile Service Manager - update to 1.1.13
imgbased (Red Hat package) - update to 1.2.18-0.1.el8ev
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - update to 1.15.7-14.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.jbcs.el7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.0.10, 2.1.6, 2.2.2
Windows Container Support for Red Hat OpenShift - update to 2.0.1
jbcs-httpd24-mod_md (Red Hat package) - update to 2.0.8-33.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - update to 2.4.37-70.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - update to 2.9.2-60.GA.jbcs.el7
IBM Security Guardium Insights - update to 3.0.1
SonicWall Capture Client - update to 3.6.24
EasyApache - addressed in versions 4 2021-3-31, 4 2021-4-28
redhat-release-virtualization-host (Red Hat package) - update to 4.4.5-4.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.4.5-20210330.0.el8_3
Nessus Network Monitor - update to 5.13.1
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.028, 7.02.003
SonicOS - update to 7.0.1-R1456
MySQL Enterprise Monitor - update to 8.0.24
Nessus Agent - update to 8.2.4
Tenable Nessus - update to 8.13.2
MySQL Connectors - update to 8.0.24
MySQL Workbench - update to 8.0.24
SMA 100 - update to 10.2.1.0-17sv
IBM App Connect Enterprise - update to 11.0.0.13
Oracle Secure Backup - update to 18.1.0.1.0
scap-security-guide (Red Hat package) - update to 0.1.50-1.el8ev
isl (Red Hat package) - update to 0.16.1-6.el8
SINEC INS - update to 1.0.1.1
libmpc (Red Hat package) - update to 1.0.2-9.el8
openssl11 - update to 1.1.1g-3.el7
openssl (Red Hat package) - update to 1.1.1g-15.el8_3
openssl - update to 1.1.1k-1.fc34
boost (Red Hat package) - update to 1.66.0-10.el8
zip (Red Hat package) - update to 3.0-23.el8
JBoss Web Server - addressed in versions 3.1 SP12, 5.4.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
libxcrypt (Red Hat package) - update to 4.1.1-4.el8
make (Red Hat package) - update to 4.2.1-10.el8
IBM Safer Payments - addressed in versions 6.1.0.08, 6.2.1.03
gcc (Red Hat package) - update to 8.3.1-5.1.el8
dyninst (Red Hat package) - update to 10.1.0-4.el8
nodejs10 - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-docs - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
npm10 - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-devel - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-debugsource - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-debuginfo - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs12-docs - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
npm12 - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-devel - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-debugsource - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-debuginfo - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12 - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
PowerProtect Data Manager - update to 19.19.0-15
tbb (Red Hat package) - update to 2018.2-9.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Arch Linux update for openssl
- FreeBSD update for OpenSSL
- Gentoo update for OpenSSL
- cPanel EasyApache update for openssl
- Red Hat Enterprise Linux 8 update for openssl
- Tenable Nessus update for OpenSSL
- Multiple vulnerabilities in Tenable Nessus Agent
- Multiple vulnerabilities in Red Hat Virtualization for RHEL 8
- Multiple vulnerabilities in Red Hat JBoss Enterprise Web Server
- Multiple vulnerabilities in Red Hat JBoss Core Services
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in Oracle Secure Global Desktop
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Red Hat OpenShift Serverless update for golang
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Multiple vulnerabilities in CPanel EasyApache
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- SonicWall products update for OpenSSL
- Security features bypass in MySQL Connectors
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Security features bypass in Microsoft Visual Studio
- Security features bypass in Oracle Secure Backup
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Siemens SINEC INS
- Security features bypass in Enterprise Manager for Storage Management
- Multiple Vulnerabilities in IBM Netcool Agile Service Manager
- SUSE update for nodejs10
- SUSE update for nodejs12
- SUSE update for nodejs12
- SUSE update for nodejs10
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Integration Bus and IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Security Verify products
- Multiple vulnerabilities in IBM Security Verify Bridge
- Multiple vulnerabilities in IBM Security Guardium Insights
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Fedora 34 update for openssl
- Fedora EPEL 7 update for openssl11
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2