During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:hp:operations_agent:11.14:*:*:*:*:*:*:*",
"cpe:2.3:a:hp:operations_agent:11.15:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "hp:operations_agent",
"extracted_events": [
{
"last_affected": "11.14"
},
{
"last_affected": "11.15"
}
]
}
]
}