Cryptographic issues in OpenSSL - CVE-2021-4160

 

Cryptographic issues in OpenSSL - CVE-2021-4160

Published: January 28, 2022 / Updated: October 2, 2024


Vulnerability identifier: #VU60166
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4160
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to decrypt TLS traffic.

The vulnerability exists due to BN_mod_exp may produce incorrect results on MIPS. A remote attacker can decrypt TLS traffic. According to vendor, multiple EC algorithms are affected, including some of the TLS 1.3 default curves. 

Successful exploitation of the vulnerability requires certain pre-requisites for attack, such as obtaining and  reusing private keys. 


Affected software

OpenSSL
Gentoo Linux
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Db2 Rest
IBM Aspera Shares
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
MobileFirst Platform
Dell EMC OS9
openssl (Debian package)
dev-libs/openssl
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Sterling Control Center
IBM Rational Build Forge
IBM Spectrum Protect Plus
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Aspera Orchestrator
Engineering Workflow Management
IBM MQ for HPE NonStop
Steel Belted Radius Carrier Edition
InfoSphere Master Data Management
NetWorker
Nessus Network Monitor
VMware Horizon Client
PeopleSoft Enterprise PeopleTools
IBM Cognos Analytics
IBM App Connect Enterprise
Engineering Lifecycle Management
Cisco Jabber
Cisco Webex Meetings
SINEC INS
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
IBM Security Verify Access

How to mitigate CVE-2021-4160

Install updates from vendor's website.

OpenSSL - addressed in versions 1.1.1m, 3.0.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
openssl (Debian package) - addressed in versions 1.1.1k-1+deb11u2, 1.1.1d-0+deb10u8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
Nessus Network Monitor - update to 6.0.1
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Sterling Control Center - update to 6.1.3.0.14
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.24
IBM App Connect Enterprise - addressed in versions 11.0.0.17, 12.0.4.0
IBM Spectrum Protect Plus - update to 10.1.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
SINEC INS - update to 1.0 SP2
Db2 Rest - update to 1.0.0.304
dev-libs/openssl - update to 1.1.1q
Netcool Operations Insight - update to 1.6.8
IBM Aspera Shares - update to 1.10.0 PL4
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Cloud Pak for Watson AIOps - update to 4.2.1
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
MobileFirst Platform - addressed in versions 8.0.2022042909, 8.0.2022050611, 8.0.2022050908
IBM MQ for HPE NonStop - update to 8.1.0.10
Steel Belted Radius Carrier Edition - update to 8.6.0R16
Dell EMC OS9 - update to 9.14.1.12
IBM Security Verify Access - update to 10.0.7.0
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.3
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins