An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signaturealgorithms extension (where it was present in the initial ClientHello), but includes a signaturealgorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "10.1.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mcafee:web_gateway:10.1.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.2.19"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mcafee:web_gateway:8.2.19:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "9.2.10"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mcafee:web_gateway:9.2.10:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "10.1.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mcafee:web_gateway_cloud_service:10.1.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.2.19"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mcafee:web_gateway_cloud_service:8.2.19:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "9.2.10"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mcafee:web_gateway_cloud_service:9.2.10:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "10.0.0"
},
{
"last_affected": "10.12.0"
},
{
"introduced": "12.0.0"
},
{
"last_affected": "12.12.0"
},
{
"introduced": "14.0.0"
},
{
"last_affected": "14.14.0"
},
{
"introduced": "15.0.0"
},
{
"fixed": "15.14.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*"
},
{
"extracted_events": [
{
"introduced": "10.13.0"
},
{
"last_affected": "10.24.0"
},
{
"introduced": "12.13.0"
},
{
"fixed": "12.22.1"
},
{
"introduced": "14.15.0"
},
{
"fixed": "14.16.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*"
},
{
"extracted_events": [
{
"introduced": "1.1.1"
},
{
"fixed": "1.1.1k"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "12.6.0.0.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:communications_communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "13.4.0.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:enterprise_manager_for_storage_management:13.4.0.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "9.2.6.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.57"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.58"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.59"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "17.7"
},
{
"last_affected": "17.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "19.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "20.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "21.12"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "18.1.0.1.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:secure_backup:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "5.6"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.8"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "1.6.0.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:simatic_logon:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "1.5-sp3_update_1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:simatic_logon:1.5:sp3_update_1:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "1.0.1.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "1.0-NA"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinec_nms:1.0:-:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "1.0-sp1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinec_nms:1.0:sp1:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "14.0-NA"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinema_server:14.0:-:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "14.0-sp1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinema_server:14.0:sp1:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "14.0-sp2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinema_server:14.0:sp2:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "14.0-sp2_update1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinema_server:14.0:sp2_update1:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "14.0-sp2_update2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:siemens:sinema_server:14.0:sp2_update2:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "3.5"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:sonicwall:capture_client:3.5:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "6.0.9"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:log_correlation_engine:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "8.13.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "5.11.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:nessus_network_monitor:5.11.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "5.11.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:nessus_network_monitor:5.11.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "5.12.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:nessus_network_monitor:5.12.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "5.12.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:nessus_network_monitor:5.12.1:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "5.13.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:nessus_network_monitor:5.13.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "5.13.0"
},
{
"last_affected": "5.17.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "r80.40"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:checkpoint:multi-domain_management_firmware:r80.40:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "r81"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:checkpoint:multi-domain_management_firmware:r81:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "r80.40"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "r81"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "r80.40"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:checkpoint:quantum_security_management_firmware:r80.40:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "r81"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:checkpoint:quantum_security_management_firmware:r81:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "34"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "12.2-NA"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "12.2-p1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "12.2-p2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "6.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:ruggedcom_rcm1224_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "6.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_m-800_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "4.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_s602_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "4.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_s612_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "6.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "4.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_s623_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "4.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_s627-2m_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_sc-600_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_w1700_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "6.5"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_w700_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "4.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "4.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "4.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xf-200ba_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "6.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "4.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "4.3"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xr-300wg_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "6.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xr524-8c_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "6.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xr526-8c_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "6.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xr528-6m_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"fixed": "6.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:scalance_xr552-12_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "1.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_cloud_connect_7_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "3.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_cp_1242-7_gprs_v2_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "3.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp1243-7_lte_eu_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "3.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp1243-7_lte_us_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "3.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp_1243-1_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "3.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp_1243-8_irc_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_irc_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2.2"
},
{
"fixed": "3.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2.1"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp_1543sp-1_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "1.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "9.1.0.7"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_pdm_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2019"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "2.0"
},
{
"fixed": "2.2"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"introduced": "10.2.0.0"
},
{
"fixed": "10.2.1.0-17sv"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:sonicwall:sma100_firmware:*:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "7.0.1.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:sonicwall:sonicos:7.0.1.0:*:*:*:*:*:*:*"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "21.2"
},
{
"last_affected": "19.3.5"
},
{
"last_affected": "20.3.1.2"
},
{
"last_affected": "21.0.0.2"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:oracle:essbase:21.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:graalvm:19.3.5:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:20.3.1.2:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:oracle:graalvm:21.0.0.2:*:*:*:enterprise:*:*:*"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
},
{
"last_affected": "a9.4"
},
{
"last_affected": "8.0.23"
},
{
"last_affected": "5.7.33"
},
{
"introduced": "8.0.15"
},
{
"last_affected": "8.0.23"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_connectors:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*"
]
}