Get real-time updates on Telegram
CVE-2021-3711: openssl from 1.1.1 (inclusive), before 1.1.1l (exclusive); +31 more affected products
CVE-2021-3711. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.87816 (percentile 0.9976), scored 2026-10-08.
Affected technology
openssl · from 1.1.1 (inclusive), before 1.1.1l (exclusive)
openssl
debian linux · 10.0
debian
debian linux · 11.0
debian
active iq unified manager · Version not applicable in the source CPE
netapp
clustered data ontap · Version not applicable in the source CPE
netapp
clustered data ontap antivirus connector · Version not applicable in the source CPE
netapp
e-series santricity os controller · from 11.0 (inclusive), through 11.50.2 (inclusive)
netapp
hci management node · Version not applicable in the source CPE
netapp
manageability software development kit · Version not applicable in the source CPE
netapp
oncommand insight · Version not applicable in the source CPE
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
santricity smi-s provider · Version not applicable in the source CPE
netapp
snapcenter · Version not applicable in the source CPE
netapp
solidfire · Version not applicable in the source CPE
netapp
storage encryption · Version not applicable in the source CPE
netapp
communications cloud native core security edge protection proxy · 1.7.0
oracle
communications cloud native core unified data repository · 1.15.0
oracle
communications session border controller · 8.4
oracle
communications session border controller · 9.0
oracle
communications unified session manager · 8.2.5
oracle
communications unified session manager · 8.4.5
oracle
enterprise communications broker · 3.2.0
oracle
enterprise communications broker · 3.3.0
oracle
enterprise session border controller · 8.4
oracle
enterprise session border controller · 9.0
oracle
essbase · before 11.1.2.4.47 (exclusive)
oracle
essbase · from 21.1 (inclusive), before 21.3 (exclusive)
oracle
health sciences inform publisher · 6.2.1.1
oracle
health sciences inform publisher · 6.3.1.1
oracle
jd edwards enterpriseone tools · before 9.2.6.3 (exclusive)
oracle
jd edwards world security · a9.4
oracle
mysql connectors · through 8.0.27 (inclusive)
oracle
mysql enterprise monitor · through 8.0.25 (inclusive)
oracle
mysql server · from 5.7.0 (inclusive), through 5.7.35 (inclusive)
oracle
mysql server · from 8.0.0 (inclusive), through 8.0.26 (inclusive)
oracle
peoplesoft enterprise peopletools · 8.57
oracle
peoplesoft enterprise peopletools · 8.58
oracle
peoplesoft enterprise peopletools · 8.59
oracle
zfs storage appliance kit · 8.8
oracle
nessus network monitor · through 5.13.1 (inclusive)
tenable
tenable.sc · from 5.16.0 (inclusive), through 5.19.1 (inclusive)
tenable
OpenSSL · Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)
OpenSSL
Component: Not specified by the source
Function: EVP_PKEY_decrypt, twice
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-120
- CCR priority
- 61.2 /100 (P2)
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.87816 · percentile 0.9976 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-3711.html