Cryptographic issues in OpenSSL - CVE-2021-4160
Published: January 28, 2022 / Updated: October 2, 2024
Vulnerability details
The vulnerability allows a remote attacker to decrypt TLS traffic.
The vulnerability exists due to BN_mod_exp may produce incorrect results on MIPS. A remote attacker can decrypt TLS traffic. According to vendor, multiple EC algorithms are affected, including some of the TLS 1.3 default curves.
Successful exploitation of the vulnerability requires certain pre-requisites for attack, such as obtaining and reusing private keys.
Affected software
Gentoo Linux
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Db2 Rest
IBM Aspera Shares
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
MobileFirst Platform
Dell EMC OS9
openssl (Debian package)
dev-libs/openssl
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Sterling Control Center
IBM Rational Build Forge
IBM Spectrum Protect Plus
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Aspera Orchestrator
Engineering Workflow Management
IBM MQ for HPE NonStop
Steel Belted Radius Carrier Edition
InfoSphere Master Data Management
NetWorker
Nessus Network Monitor
VMware Horizon Client
PeopleSoft Enterprise PeopleTools
IBM Cognos Analytics
IBM App Connect Enterprise
Engineering Lifecycle Management
Cisco Jabber
Cisco Webex Meetings
SINEC INS
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
IBM Security Verify Access
How to mitigate CVE-2021-4160
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
openssl (Debian package) - addressed in versions 1.1.1k-1+deb11u2, 1.1.1d-0+deb10u8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
Nessus Network Monitor - update to 6.0.1
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Sterling Control Center - update to 6.1.3.0.14
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.24
IBM App Connect Enterprise - addressed in versions 11.0.0.17, 12.0.4.0
IBM Spectrum Protect Plus - update to 10.1.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
SINEC INS - update to 1.0 SP2
Db2 Rest - update to 1.0.0.304
dev-libs/openssl - update to 1.1.1q
Netcool Operations Insight - update to 1.6.8
IBM Aspera Shares - update to 1.10.0 PL4
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Cloud Pak for Watson AIOps - update to 4.2.1
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
MobileFirst Platform - addressed in versions 8.0.2022042909, 8.0.2022050611, 8.0.2022050908
IBM MQ for HPE NonStop - update to 8.1.0.10
Steel Belted Radius Carrier Edition - update to 8.6.0R16
Dell EMC OS9 - update to 9.14.1.12
IBM Security Verify Access - update to 10.0.7.0
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.3
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Information disclosure in OpenSSL
- Debian update for openssl
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- IBM App Connect Enterprise update for Node.js
- Multiple vulnerabilities in IBM WIoTP MessageGateway/IoT MessageSight
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Multiple vulnerabilities in Siemens SINEC INS
- Information disclosure in Dell EMC OS9
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Aspera Faspex
- Gentoo update for OpenSSL
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Multiple vulnerabilities in IBM Sterling Control Center
- Multiple vulnerabilities in IBM Cognos Analytics
- Cryptographic issues in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Cryptographic issues in IBM Aspera Orchestrator
- Cryptographic issues in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Aspera Shares
- IBM InfoSphere Master Data Management update for OpenSSL
- IBM MQ for HPE NonStop update for OpenSSL
- IBM MobileFirst Foundation update for OpenSSL