CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-3449: openssl from 1.1.1 (inclusive), before 1.1.1k (exclusive); +106 more affected products

CVE-2021-3449. CVSS 3.1 base score 5.9 (MEDIUM, NVD). EPSS 0.63542 (percentile 0.99195), scored 2026-10-08.

Affected technology

openssl · from 1.1.1 (inclusive), before 1.1.1k (exclusive)
openssl

debian linux · 9.0
debian

debian linux · 10.0
debian

freebsd · 12.2
freebsd

freebsd · 12.2 · update p1
freebsd

freebsd · 12.2 · update p2
freebsd

active iq unified manager · Version not applicable in the source CPE
netapp

cloud volumes ontap mediator · Version not applicable in the source CPE
netapp

e-series performance analyzer · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

ontap select deploy administration utility · Version not applicable in the source CPE
netapp

santricity smi-s provider · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

storagegrid · Version not applicable in the source CPE
netapp

log correlation engine · before 6.0.9 (exclusive)
tenable

nessus · through 8.13.1 (inclusive)
tenable

nessus network monitor · 5.11.0
tenable

nessus network monitor · 5.11.1
tenable

nessus network monitor · 5.12.0
tenable

nessus network monitor · 5.12.1
tenable

nessus network monitor · 5.13.0
tenable

tenable.sc · from 5.13.0 (inclusive), through 5.17.0 (inclusive)
tenable

fedora · 34
fedoraproject

web gateway · 8.2.19
mcafee

web gateway · 9.2.10
mcafee

web gateway · 10.1.1
mcafee

web gateway cloud service · 8.2.19
mcafee

web gateway cloud service · 9.2.10
mcafee

web gateway cloud service · 10.1.1
mcafee

quantum security management firmware · r80.40
checkpoint

quantum security management firmware · r81
checkpoint

multi-domain management firmware · r80.40
checkpoint

multi-domain management firmware · r81
checkpoint

quantum security gateway firmware · r80.40
checkpoint

quantum security gateway firmware · r81
checkpoint

communications communications policy management · 12.6.0.0.0
oracle

enterprise manager for storage management · 13.4.0.0
oracle

essbase · 21.2
oracle

graalvm · 19.3.5
oracle

graalvm · 20.3.1.2
oracle

graalvm · 21.0.0.2
oracle

jd edwards enterpriseone tools · before 9.2.6.0 (exclusive)
oracle

jd edwards world security · a9.4
oracle

mysql connectors · through 8.0.23 (inclusive)
oracle

mysql server · through 5.7.33 (inclusive)
oracle

mysql server · from 8.0.15 (inclusive), through 8.0.23 (inclusive)
oracle

mysql workbench · through 8.0.23 (inclusive)
oracle

peoplesoft enterprise peopletools · 8.57
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise peopletools · 8.59
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 19.12
oracle

primavera unifier · 20.12
oracle

primavera unifier · 21.12
oracle

secure backup · before 18.1.0.1.0 (exclusive)
oracle

secure global desktop · 5.6
oracle

zfs storage appliance kit · 8.8
oracle

sma100 firmware · from 10.2.0.0 (inclusive), before 10.2.1.0-17sv (exclusive)
sonicwall

capture client · 3.5
sonicwall

sonicos · 7.0.1.0
sonicwall

ruggedcom rcm1224 firmware · from 6.2 (inclusive)
siemens

scalance lpe9403 firmware · Exact affected versions not specified by the source
siemens

scalance m-800 firmware · from 6.2 (inclusive)
siemens

scalance s602 firmware · from 4.1 (inclusive)
siemens

scalance s612 firmware · from 4.1 (inclusive)
siemens

scalance s615 firmware · from 6.2 (inclusive)
siemens

scalance s623 firmware · from 4.1 (inclusive)
siemens

scalance s627-2m firmware · from 4.1 (inclusive)
siemens

scalance sc-600 firmware · from 2.0 (inclusive)
siemens

scalance w700 firmware · from 6.5 (inclusive)
siemens

scalance w1700 firmware · from 2.0 (inclusive)
siemens

scalance xb-200 firmware · before 4.3 (exclusive)
siemens

scalance xc-200 firmware · before 4.3 (exclusive)
siemens

scalance xf-200ba firmware · before 4.3 (exclusive)
siemens

scalance xm-400 firmware · before 6.4 (exclusive)
siemens

scalance xp-200 firmware · before 4.3 (exclusive)
siemens

scalance xr-300wg firmware · before 4.3 (exclusive)
siemens

scalance xr524-8c firmware · before 6.4 (exclusive)
siemens

scalance xr526-8c firmware · before 6.4 (exclusive)
siemens

scalance xr528-6m firmware · before 6.4 (exclusive)
siemens

scalance xr552-12 firmware · before 6.4 (exclusive)
siemens

simatic cloud connect 7 firmware · from 1.1 (inclusive)
siemens

simatic cloud connect 7 firmware · Version not applicable in the source CPE
siemens

simatic cp 1242-7 gprs v2 firmware · from 3.1 (inclusive)
siemens

simatic cp 1242-7 gprs v2 firmware · Version not applicable in the source CPE
siemens

simatic hmi basic panels 2nd generation firmware · Exact affected versions not specified by the source
siemens

simatic hmi comfort outdoor panels firmware · Exact affected versions not specified by the source
siemens

simatic hmi ktp mobile panels firmware · Exact affected versions not specified by the source
siemens

simatic mv500 firmware · Exact affected versions not specified by the source
siemens

simatic net cp 1243-1 firmware · from 3.1 (inclusive)
siemens

simatic net cp1243-7 lte eu firmware · from 3.1 (inclusive)
siemens

simatic net cp1243-7 lte us firmware · from 3.1 (inclusive)
siemens

simatic net cp 1243-8 irc firmware · from 3.1 (inclusive)
siemens

simatic net cp 1542sp-1 irc firmware · from 2.1 (inclusive)
siemens

simatic net cp 1543-1 firmware · from 2.2 (inclusive), before 3.0 (exclusive)
siemens

simatic net cp 1543sp-1 firmware · from 2.1 (inclusive)
siemens

simatic net cp 1545-1 firmware · from 1.0 (inclusive)
siemens

simatic pcs 7 telecontrol firmware · Exact affected versions not specified by the source
siemens

simatic pcs neo firmware · Exact affected versions not specified by the source
siemens

simatic pdm firmware · from 9.1.0.7 (inclusive)
siemens

simatic process historian opc ua server firmware · from 2019 (inclusive)
siemens

simatic rf166c firmware · Exact affected versions not specified by the source
siemens

simatic rf185c firmware · Exact affected versions not specified by the source
siemens

simatic rf186c firmware · Exact affected versions not specified by the source
siemens

simatic rf186ci firmware · Exact affected versions not specified by the source
siemens

simatic rf188c firmware · Exact affected versions not specified by the source
siemens

simatic rf188ci firmware · Exact affected versions not specified by the source
siemens

simatic rf360r firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1211c firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1212c firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1212fc firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1214 fc firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1214c firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1215 fc firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1215c firmware · Exact affected versions not specified by the source
siemens

simatic s7-1200 cpu 1217c firmware · Exact affected versions not specified by the source
siemens

simatic s7-1500 cpu 1518-4 pn/dp mfp firmware · Exact affected versions not specified by the source
siemens

sinamics connect 300 firmware · Exact affected versions not specified by the source
siemens

tim 1531 irc firmware · from 2.0 (inclusive), before 2.2 (exclusive)
siemens

simatic logon · from 1.6.0.2 (inclusive)
siemens

simatic logon · 1.5 · update sp3_update_1
siemens

simatic wincc runtime advanced · Exact affected versions not specified by the source
siemens

simatic wincc telecontrol · Version not applicable in the source CPE
siemens

sinec nms · 1.0
siemens

sinec nms · 1.0 · update sp1
siemens

sinec pni · Version not applicable in the source CPE
siemens

sinema server · 14.0
siemens

sinema server · 14.0 · update sp1
siemens

sinema server · 14.0 · update sp2
siemens

sinema server · 14.0 · update sp2_update1
siemens

sinema server · 14.0 · update sp2_update2
siemens

sinumerik opc ua server · Exact affected versions not specified by the source
siemens

tia administrator · Exact affected versions not specified by the source
siemens

sinec infrastructure network services · before 1.0.1.1 (exclusive)
siemens

node.js · from 10.0.0 (inclusive), through 10.12.0 (inclusive)
nodejs

node.js · from 10.13.0 (inclusive), through 10.24.0 (inclusive)
nodejs

node.js · from 12.0.0 (inclusive), through 12.12.0 (inclusive)
nodejs

node.js · from 12.13.0 (inclusive), before 12.22.1 (exclusive)
nodejs

node.js · from 14.0.0 (inclusive), through 14.14.0 (inclusive)
nodejs

node.js · from 14.15.0 (inclusive), before 14.16.1 (exclusive)
nodejs

node.js · from 15.0.0 (inclusive), before 15.14.0 (exclusive)
nodejs

OpenSSL · Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j)
OpenSSL

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 5.9/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-476
CCR priority
39.5 /100 (P4)
CVSS 3.1
5.9 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.63542 · percentile 0.99195 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-3449.html