CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-3450: openssl from 1.1.1h (inclusive), before 1.1.1k (exclusive); +33 more affected products

CVE-2021-3450. CVSS 3.1 base score 7.4 (HIGH, NVD). EPSS 0.18339 (percentile 0.97161), scored 2026-10-08.

Affected technology

openssl · from 1.1.1h (inclusive), before 1.1.1k (exclusive)
openssl

freebsd · 12.2
freebsd

freebsd · 12.2 · update p1
freebsd

freebsd · 12.2 · update p2
freebsd

santricity smi-s provider firmware · Version not applicable in the source CPE
netapp

storagegrid firmware · Version not applicable in the source CPE
netapp

linux · Version not applicable in the source CPE
windriver

linux · 17.0
windriver

linux · 18.0
windriver

linux · 19.0
windriver

cloud volumes ontap mediator · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

ontap select deploy administration utility · Version not applicable in the source CPE
netapp

storagegrid · Version not applicable in the source CPE
netapp

fedora · 34
fedoraproject

nessus · through 8.13.1 (inclusive)
tenable

nessus agent · from 8.2.1 (inclusive), through 8.2.3 (inclusive)
tenable

nessus network monitor · 5.11.0
tenable

nessus network monitor · 5.11.1
tenable

nessus network monitor · 5.12.0
tenable

nessus network monitor · 5.12.1
tenable

nessus network monitor · 5.13.0
tenable

commerce guided search · 11.3.2
oracle

enterprise manager for storage management · 13.4.0.0
oracle

graalvm · 19.3.5
oracle

graalvm · 20.3.1.2
oracle

graalvm · 21.0.0.2
oracle

jd edwards enterpriseone tools · before 9.2.6.0 (exclusive)
oracle

jd edwards world security · a9.4
oracle

mysql connectors · through 8.0.23 (inclusive)
oracle

mysql enterprise monitor · through 8.0.23 (inclusive)
oracle

mysql server · through 5.7.33 (inclusive)
oracle

mysql server · from 8.0.15 (inclusive), through 8.0.23 (inclusive)
oracle

mysql workbench · through 8.0.23 (inclusive)
oracle

peoplesoft enterprise peopletools · from 8.57 (inclusive), through 8.59 (inclusive)
oracle

secure backup · before 18.1.0.1.0 (exclusive)
oracle

secure global desktop · 5.6
oracle

weblogic server · 12.2.1.4.0
oracle

weblogic server · 14.1.1.0.0
oracle

web gateway · 8.2.19
mcafee

web gateway · 9.2.10
mcafee

web gateway · 10.1.1
mcafee

web gateway cloud service · 8.2.19
mcafee

web gateway cloud service · 9.2.10
mcafee

web gateway cloud service · 10.1.1
mcafee

sma100 firmware · before 10.2.1.0-17sv (exclusive)
sonicwall

capture client · before 3.6.24 (exclusive)
sonicwall

email security · before 10.0.11 (exclusive)
sonicwall

sonicos · through 7.0.1-r1456 (inclusive)
sonicwall

node.js · from 10.0.0 (inclusive), before 10.24.1 (exclusive)
nodejs

node.js · from 12.0.0 (inclusive), before 12.22.1 (exclusive)
nodejs

node.js · from 14.0.0 (inclusive), before 14.16.1 (exclusive)
nodejs

node.js · from 15.0.0 (inclusive), before 15.14.0 (exclusive)
nodejs

OpenSSL · Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j)
OpenSSL

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

NVD’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-295
CCR priority
34.2 /100 (P4)
CVSS 3.1
7.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N · NVD
EPSS
0.18339 · percentile 0.97161 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-3450.html