Get real-time updates on Telegram
CVE-2021-3450: openssl from 1.1.1h (inclusive), before 1.1.1k (exclusive); +33 more affected products
CVE-2021-3450. CVSS 3.1 base score 7.4 (HIGH, NVD). EPSS 0.18339 (percentile 0.97161), scored 2026-10-08.
Affected technology
openssl · from 1.1.1h (inclusive), before 1.1.1k (exclusive)
openssl
freebsd · 12.2
freebsd
freebsd · 12.2 · update p1
freebsd
freebsd · 12.2 · update p2
freebsd
santricity smi-s provider firmware · Version not applicable in the source CPE
netapp
storagegrid firmware · Version not applicable in the source CPE
netapp
linux · Version not applicable in the source CPE
windriver
linux · 17.0
windriver
linux · 18.0
windriver
linux · 19.0
windriver
cloud volumes ontap mediator · Version not applicable in the source CPE
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
ontap select deploy administration utility · Version not applicable in the source CPE
netapp
storagegrid · Version not applicable in the source CPE
netapp
fedora · 34
fedoraproject
nessus · through 8.13.1 (inclusive)
tenable
nessus agent · from 8.2.1 (inclusive), through 8.2.3 (inclusive)
tenable
nessus network monitor · 5.11.0
tenable
nessus network monitor · 5.11.1
tenable
nessus network monitor · 5.12.0
tenable
nessus network monitor · 5.12.1
tenable
nessus network monitor · 5.13.0
tenable
commerce guided search · 11.3.2
oracle
enterprise manager for storage management · 13.4.0.0
oracle
graalvm · 19.3.5
oracle
graalvm · 20.3.1.2
oracle
graalvm · 21.0.0.2
oracle
jd edwards enterpriseone tools · before 9.2.6.0 (exclusive)
oracle
jd edwards world security · a9.4
oracle
mysql connectors · through 8.0.23 (inclusive)
oracle
mysql enterprise monitor · through 8.0.23 (inclusive)
oracle
mysql server · through 5.7.33 (inclusive)
oracle
mysql server · from 8.0.15 (inclusive), through 8.0.23 (inclusive)
oracle
mysql workbench · through 8.0.23 (inclusive)
oracle
peoplesoft enterprise peopletools · from 8.57 (inclusive), through 8.59 (inclusive)
oracle
secure backup · before 18.1.0.1.0 (exclusive)
oracle
secure global desktop · 5.6
oracle
weblogic server · 12.2.1.4.0
oracle
weblogic server · 14.1.1.0.0
oracle
web gateway · 8.2.19
mcafee
web gateway · 9.2.10
mcafee
web gateway · 10.1.1
mcafee
web gateway cloud service · 8.2.19
mcafee
web gateway cloud service · 9.2.10
mcafee
web gateway cloud service · 10.1.1
mcafee
sma100 firmware · before 10.2.1.0-17sv (exclusive)
sonicwall
capture client · before 3.6.24 (exclusive)
sonicwall
email security · before 10.0.11 (exclusive)
sonicwall
sonicos · through 7.0.1-r1456 (inclusive)
sonicwall
node.js · from 10.0.0 (inclusive), before 10.24.1 (exclusive)
nodejs
node.js · from 12.0.0 (inclusive), before 12.22.1 (exclusive)
nodejs
node.js · from 14.0.0 (inclusive), before 14.16.1 (exclusive)
nodejs
node.js · from 15.0.0 (inclusive), before 15.14.0 (exclusive)
nodejs
OpenSSL · Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j)
OpenSSL
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
NVD’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-295
- CCR priority
- 34.2 /100 (P4)
- CVSS 3.1
- 7.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N · NVD
- EPSS
- 0.18339 · percentile 0.97161 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-3450.html