#VU60166 Cryptographic issues in OpenSSL - CVE-2021-4160
Published: January 28, 2022 / Updated: October 2, 2024
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to decrypt TLS traffic.
The vulnerability exists due to BN_mod_exp may produce incorrect results on MIPS. A remote attacker can decrypt TLS traffic. According to vendor, multiple EC algorithms are affected, including some of the TLS 1.3 default curves.
Successful exploitation of the vulnerability requires certain pre-requisites for attack, such as obtaining and reusing private keys.