CYBER CODE RED

Get real-time updates on Telegram

P2Verified

CVE-2021-3711: openssl from 1.1.1 (inclusive), before 1.1.1l (exclusive); +31 more affected products

CVE-2021-3711. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.87816 (percentile 0.9976), scored 2026-10-08.

Affected technology

openssl · from 1.1.1 (inclusive), before 1.1.1l (exclusive)
openssl

debian linux · 10.0
debian

debian linux · 11.0
debian

active iq unified manager · Version not applicable in the source CPE
netapp

clustered data ontap · Version not applicable in the source CPE
netapp

clustered data ontap antivirus connector · Version not applicable in the source CPE
netapp

e-series santricity os controller · from 11.0 (inclusive), through 11.50.2 (inclusive)
netapp

hci management node · Version not applicable in the source CPE
netapp

manageability software development kit · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

santricity smi-s provider · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

solidfire · Version not applicable in the source CPE
netapp

storage encryption · Version not applicable in the source CPE
netapp

communications cloud native core security edge protection proxy · 1.7.0
oracle

communications cloud native core unified data repository · 1.15.0
oracle

communications session border controller · 8.4
oracle

communications session border controller · 9.0
oracle

communications unified session manager · 8.2.5
oracle

communications unified session manager · 8.4.5
oracle

enterprise communications broker · 3.2.0
oracle

enterprise communications broker · 3.3.0
oracle

enterprise session border controller · 8.4
oracle

enterprise session border controller · 9.0
oracle

essbase · before 11.1.2.4.47 (exclusive)
oracle

essbase · from 21.1 (inclusive), before 21.3 (exclusive)
oracle

health sciences inform publisher · 6.2.1.1
oracle

health sciences inform publisher · 6.3.1.1
oracle

jd edwards enterpriseone tools · before 9.2.6.3 (exclusive)
oracle

jd edwards world security · a9.4
oracle

mysql connectors · through 8.0.27 (inclusive)
oracle

mysql enterprise monitor · through 8.0.25 (inclusive)
oracle

mysql server · from 5.7.0 (inclusive), through 5.7.35 (inclusive)
oracle

mysql server · from 8.0.0 (inclusive), through 8.0.26 (inclusive)
oracle

peoplesoft enterprise peopletools · 8.57
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise peopletools · 8.59
oracle

zfs storage appliance kit · 8.8
oracle

nessus network monitor · through 5.13.1 (inclusive)
tenable

tenable.sc · from 5.16.0 (inclusive), through 5.19.1 (inclusive)
tenable

OpenSSL · Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)
OpenSSL

Component: Not specified by the source
Function: EVP_PKEY_decrypt, twice

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-120
CCR priority
61.2 /100 (P2)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.87816 · percentile 0.9976 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-3711.html