IM
IronMonkey Threat Research

CVE-2021-3449 MEDIUM

Published: 2021-03-25 | Last Modified: 2024-11-21 | Status: Modified

Description

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Additional Descriptions (1)

Un servidor OpenSSL TLS puede cometer un fallo si un cliente envía un mensaje ClientHello de renegociación diseñado maliciosamente. Si una renegociación de TLSv1.2 ClientHello omite la extensión signature_algorithms (donde estaba presente en el ClientHello inicial), pero incluye una extensión signature_algorithms_cert, se producirá una desreferencia del puntero NULL, lo que conllevará un bloqueo y un ataque de denegación de servicio. Un servidor solo es vulnerable si tiene TLSv1.2 y la renegociación habilitada (que es la configuración predeterminada). Los clientes de OpenSSL TLS no están afectados por este problema. Todas las versiones de OpenSSL versión 1.1.1 están afectadas por este problema. Los usuarios de estas versiones deben actualizar a OpenSSL versión 1.1.1k. OpenSSL versión 1.0.2 no está afectado por este problema. Corregido en OpenSSL versión 1.1.1k (Afectadas versiones 1.1.1-1.1.1j)

CVSS Metrics

Base Score: 5.9 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.2

Impact Score: 3.6

Base Score: 4.3 (MEDIUM)

AV:N/AC:M/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-476

Affected Products

Vendor Product Version Update Type
openssl openssl * <built-in method update of dict object at 0x72a9ccfa7c00> Application
debian debian_linux 9.0 <built-in method update of dict object at 0x72a9b0b6ba00> Operating System
debian debian_linux 10.0 <built-in method update of dict object at 0x72a9b0b6ad80> Operating System
freebsd freebsd 12.2 <built-in method update of dict object at 0x72a9b0a77280> Operating System
freebsd freebsd 12.2 <built-in method update of dict object at 0x72a9ccfa7b40> Operating System
freebsd freebsd 12.2 <built-in method update of dict object at 0x72a9ccd2a2c0> Operating System
netapp active_iq_unified_manager - <built-in method update of dict object at 0x72a9b0b694c0> Application
netapp cloud_volumes_ontap_mediator - <built-in method update of dict object at 0x72a9b0b6a700> Application
netapp e-series_performance_analyzer - <built-in method update of dict object at 0x72a9b0b69780> Application
netapp oncommand_insight - <built-in method update of dict object at 0x72a9ccd2a040> Application
netapp oncommand_workflow_automation - <built-in method update of dict object at 0x72a9b0b6bb40> Application
netapp ontap_select_deploy_administration_utility - <built-in method update of dict object at 0x72a9b0b6bd40> Application
netapp santricity_smi-s_provider - <built-in method update of dict object at 0x72a9cd086200> Application
netapp snapcenter - <built-in method update of dict object at 0x72a9b0b6b1c0> Application
netapp storagegrid - <built-in method update of dict object at 0x72a9b0b6b0c0> Application
tenable log_correlation_engine * <built-in method update of dict object at 0x72a9cd0840c0> Application
tenable nessus * <built-in method update of dict object at 0x72a9ccfa5cc0> Application
tenable nessus_network_monitor 5.11.0 <built-in method update of dict object at 0x72a9b0b68580> Application
tenable nessus_network_monitor 5.11.1 <built-in method update of dict object at 0x72a9b0b6b200> Application
tenable nessus_network_monitor 5.12.0 <built-in method update of dict object at 0x72a9b0a75800> Application
tenable nessus_network_monitor 5.12.1 <built-in method update of dict object at 0x72a9cd086d80> Application
tenable nessus_network_monitor 5.13.0 <built-in method update of dict object at 0x72a9b0b6ac80> Application
tenable tenable.sc * <built-in method update of dict object at 0x72a9b0b6ad00> Application
fedoraproject fedora 34 <built-in method update of dict object at 0x72a9b0b6bec0> Operating System
mcafee web_gateway 8.2.19 <built-in method update of dict object at 0x72a9b0b69ec0> Application
mcafee web_gateway 9.2.10 <built-in method update of dict object at 0x72a9b0b68c00> Application
mcafee web_gateway 10.1.1 <built-in method update of dict object at 0x72a9cc876540> Application
mcafee web_gateway_cloud_service 8.2.19 <built-in method update of dict object at 0x72a9b0b68bc0> Application
mcafee web_gateway_cloud_service 9.2.10 <built-in method update of dict object at 0x72a9cd0dbdc0> Application
mcafee web_gateway_cloud_service 10.1.1 <built-in method update of dict object at 0x72a9cd0da180> Application
checkpoint quantum_security_management_firmware r80.40 <built-in method update of dict object at 0x72a9cd084080> Operating System
checkpoint quantum_security_management_firmware r81 <built-in method update of dict object at 0x72a9cd0d8c00> Operating System
checkpoint multi-domain_management_firmware r80.40 <built-in method update of dict object at 0x72a9ccd2a380> Operating System
checkpoint multi-domain_management_firmware r81 <built-in method update of dict object at 0x72a9cd0d9b40> Operating System
checkpoint quantum_security_gateway_firmware r80.40 <built-in method update of dict object at 0x72a9cd0d8800> Operating System
checkpoint quantum_security_gateway_firmware r81 <built-in method update of dict object at 0x72a9cd0db940> Operating System
oracle communications_communications_policy_management 12.6.0.0.0 <built-in method update of dict object at 0x72a9cd0d8d80> Application
oracle enterprise_manager_for_storage_management 13.4.0.0 <built-in method update of dict object at 0x72a9cd0d8e00> Application
oracle essbase 21.2 <built-in method update of dict object at 0x72a9cd0d9340> Application
oracle graalvm 19.3.5 <built-in method update of dict object at 0x72a9ccd2aa40> Application
oracle graalvm 20.3.1.2 <built-in method update of dict object at 0x72a9cd087f40> Application
oracle graalvm 21.0.0.2 <built-in method update of dict object at 0x72a9cc874580> Application
oracle jd_edwards_enterpriseone_tools * <built-in method update of dict object at 0x72a9cc427ec0> Application
oracle jd_edwards_world_security a9.4 <built-in method update of dict object at 0x72a9cc4244c0> Application
oracle mysql_connectors * <built-in method update of dict object at 0x72a9cc426240> Application
oracle mysql_server * <built-in method update of dict object at 0x72a9cc426e40> Application
oracle mysql_server * <built-in method update of dict object at 0x72a9cc426980> Application
oracle mysql_workbench * <built-in method update of dict object at 0x72a9cd06eb40> Application
oracle peoplesoft_enterprise_peopletools 8.57 <built-in method update of dict object at 0x72a9cd06e580> Application
oracle peoplesoft_enterprise_peopletools 8.58 <built-in method update of dict object at 0x72a9cd06e380> Application
oracle peoplesoft_enterprise_peopletools 8.59 <built-in method update of dict object at 0x72a9cc6f2c80> Application
oracle primavera_unifier * <built-in method update of dict object at 0x72a9cc6f26c0> Application
oracle primavera_unifier 19.12 <built-in method update of dict object at 0x72a9cc6f3200> Application
oracle primavera_unifier 20.12 <built-in method update of dict object at 0x72a9cc6f2f80> Application
oracle primavera_unifier 21.12 <built-in method update of dict object at 0x72a9cc6f1dc0> Application
oracle secure_backup * <built-in method update of dict object at 0x72a9b0c91600> Application
oracle secure_global_desktop 5.6 <built-in method update of dict object at 0x72a9b0c93e40> Application
oracle zfs_storage_appliance_kit 8.8 <built-in method update of dict object at 0x72a9b0c93c40> Application
sonicwall sma100_firmware * <built-in method update of dict object at 0x72a9b0c91d00> Operating System
sonicwall capture_client 3.5 <built-in method update of dict object at 0x72a9b0c91f40> Application
sonicwall sonicos 7.0.1.0 <built-in method update of dict object at 0x72a9b0c90540> Operating System
siemens ruggedcom_rcm1224_firmware * <built-in method update of dict object at 0x72a9b0c93cc0> Operating System
siemens scalance_lpe9403_firmware * <built-in method update of dict object at 0x72a9b0c92500> Operating System
siemens scalance_m-800_firmware * <built-in method update of dict object at 0x72a9b0c93d80> Operating System
siemens scalance_s602_firmware * <built-in method update of dict object at 0x72a9b0c90300> Operating System
siemens scalance_s612_firmware * <built-in method update of dict object at 0x72a9b0c90a80> Operating System
siemens scalance_s615_firmware * <built-in method update of dict object at 0x72a9b0c93740> Operating System
siemens scalance_s623_firmware * <built-in method update of dict object at 0x72a9b0c92cc0> Operating System
siemens scalance_s627-2m_firmware * <built-in method update of dict object at 0x72a9b0c90900> Operating System
siemens scalance_sc-600_firmware * <built-in method update of dict object at 0x72a9b0c92b40> Operating System
siemens scalance_w700_firmware * <built-in method update of dict object at 0x72a9b0c91340> Operating System
siemens scalance_w1700_firmware * <built-in method update of dict object at 0x72a9b0c90fc0> Operating System
siemens scalance_xb-200_firmware * <built-in method update of dict object at 0x72a9b09071c0> Operating System
siemens scalance_xc-200_firmware * <built-in method update of dict object at 0x72a9b09055c0> Operating System
siemens scalance_xf-200ba_firmware * <built-in method update of dict object at 0x72a9b0905640> Operating System
siemens scalance_xm-400_firmware * <built-in method update of dict object at 0x72a9b0c67dc0> Operating System
siemens scalance_xp-200_firmware * <built-in method update of dict object at 0x72a9b0c667c0> Operating System
siemens scalance_xr-300wg_firmware * <built-in method update of dict object at 0x72a9b0c66bc0> Operating System
siemens scalance_xr524-8c_firmware * <built-in method update of dict object at 0x72a9b0c66340> Operating System
siemens scalance_xr526-8c_firmware * <built-in method update of dict object at 0x72a9b0c65300> Operating System
siemens scalance_xr528-6m_firmware * <built-in method update of dict object at 0x72a9b0c64800> Operating System
siemens scalance_xr552-12_firmware * <built-in method update of dict object at 0x72a9b0c67a40> Operating System
siemens simatic_cloud_connect_7_firmware * <built-in method update of dict object at 0x72a9b0c64cc0> Operating System
siemens simatic_cloud_connect_7_firmware - <built-in method update of dict object at 0x72a9b0c646c0> Operating System
siemens simatic_cp_1242-7_gprs_v2_firmware * <built-in method update of dict object at 0x72a9b0c67f40> Operating System
siemens simatic_cp_1242-7_gprs_v2_firmware - <built-in method update of dict object at 0x72a9b0c66900> Operating System
siemens simatic_hmi_basic_panels_2nd_generation_firmware * <built-in method update of dict object at 0x72a9b0c66640> Operating System
siemens simatic_hmi_comfort_outdoor_panels_firmware * <built-in method update of dict object at 0x72a9b0c647c0> Operating System
siemens simatic_hmi_ktp_mobile_panels_firmware * <built-in method update of dict object at 0x72a9b0c64900> Operating System
siemens simatic_mv500_firmware * <built-in method update of dict object at 0x72a9b0c64100> Operating System
siemens simatic_net_cp_1243-1_firmware * <built-in method update of dict object at 0x72a9b0c67e80> Operating System
siemens simatic_net_cp1243-7_lte_eu_firmware * <built-in method update of dict object at 0x72a9b0c64380> Operating System
siemens simatic_net_cp1243-7_lte_us_firmware * <built-in method update of dict object at 0x72a9b0c64e80> Operating System
siemens simatic_net_cp_1243-8_irc_firmware * <built-in method update of dict object at 0x72a9b0c64300> Operating System
siemens simatic_net_cp_1542sp-1_irc_firmware * <built-in method update of dict object at 0x72a9b0c66040> Operating System
siemens simatic_net_cp_1543-1_firmware * <built-in method update of dict object at 0x72a9b0c641c0> Operating System
siemens simatic_net_cp_1543sp-1_firmware * <built-in method update of dict object at 0x72a9b0c64180> Operating System
siemens simatic_net_cp_1545-1_firmware * <built-in method update of dict object at 0x72a9b0c67780> Operating System
siemens simatic_pcs_7_telecontrol_firmware * <built-in method update of dict object at 0x72a9b0c67a80> Operating System
siemens simatic_pcs_neo_firmware * <built-in method update of dict object at 0x72a9b0c645c0> Operating System
siemens simatic_pdm_firmware * <built-in method update of dict object at 0x72a9b0c65200> Operating System
siemens simatic_process_historian_opc_ua_server_firmware * <built-in method update of dict object at 0x72a9b0c64480> Operating System
siemens simatic_rf166c_firmware * <built-in method update of dict object at 0x72a9b0c66a40> Operating System
siemens simatic_rf185c_firmware * <built-in method update of dict object at 0x72a9b0c64280> Operating System
siemens simatic_rf186c_firmware * <built-in method update of dict object at 0x72a9b0c66cc0> Operating System
siemens simatic_rf186ci_firmware * <built-in method update of dict object at 0x72a9b0c66400> Operating System
siemens simatic_rf188c_firmware * <built-in method update of dict object at 0x72a9b0c64f80> Operating System
siemens simatic_rf188ci_firmware * <built-in method update of dict object at 0x72a9b0c65540> Operating System
siemens simatic_rf360r_firmware * <built-in method update of dict object at 0x72a9b0c65b80> Operating System
siemens simatic_s7-1200_cpu_1211c_firmware * <built-in method update of dict object at 0x72a9b0c64c40> Operating System
siemens simatic_s7-1200_cpu_1212c_firmware * <built-in method update of dict object at 0x72a9b0c67340> Operating System
siemens simatic_s7-1200_cpu_1212fc_firmware * <built-in method update of dict object at 0x72a9b0c67c80> Operating System
siemens simatic_s7-1200_cpu_1214_fc_firmware * <built-in method update of dict object at 0x72a9b0c66a00> Operating System
siemens simatic_s7-1200_cpu_1214c_firmware * <built-in method update of dict object at 0x72a9b0c65ac0> Operating System
siemens simatic_s7-1200_cpu_1214_fc_firmware * <built-in method update of dict object at 0x72a9b0c64240> Operating System
siemens simatic_s7-1200_cpu_1215_fc_firmware * <built-in method update of dict object at 0x72a9b0c66500> Operating System
siemens simatic_s7-1200_cpu_1215c_firmware * <built-in method update of dict object at 0x72a9b0c65340> Operating System
siemens simatic_s7-1200_cpu_1217c_firmware * <built-in method update of dict object at 0x72a9b0c658c0> Operating System
siemens simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware * <built-in method update of dict object at 0x72a9b0c65f80> Operating System
siemens sinamics_connect_300_firmware * <built-in method update of dict object at 0x72a9b0c64ac0> Operating System
siemens tim_1531_irc_firmware * <built-in method update of dict object at 0x72a9b0c64340> Operating System
siemens simatic_logon * <built-in method update of dict object at 0x72a9b0c67bc0> Application
siemens simatic_logon 1.5 <built-in method update of dict object at 0x72a9b0c66d80> Application
siemens simatic_wincc_runtime_advanced * <built-in method update of dict object at 0x72a9b0c64ec0> Application
siemens simatic_wincc_telecontrol - <built-in method update of dict object at 0x72a9b0c64140> Application
siemens sinec_nms 1.0 <built-in method update of dict object at 0x72a9b0c66b80> Application
siemens sinec_nms 1.0 <built-in method update of dict object at 0x72a9b0c66c40> Application
siemens sinec_pni - <built-in method update of dict object at 0x72a9b0c67b00> Application
siemens sinema_server 14.0 <built-in method update of dict object at 0x72a9b0c67500> Application
siemens sinema_server 14.0 <built-in method update of dict object at 0x72a9b0c67400> Application
siemens sinema_server 14.0 <built-in method update of dict object at 0x72a9b0c64d80> Application
siemens sinema_server 14.0 <built-in method update of dict object at 0x72a9b0c66d00> Application
siemens sinema_server 14.0 <built-in method update of dict object at 0x72a9b0c642c0> Application
siemens sinumerik_opc_ua_server * <built-in method update of dict object at 0x72a9b0c66ec0> Application
siemens tia_administrator * <built-in method update of dict object at 0x72a9b0c664c0> Application
siemens sinec_infrastructure_network_services * <built-in method update of dict object at 0x72a9b0c64980> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c65280> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c65980> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c67380> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c65c80> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c64500> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c670c0> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c65a40> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Yes cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:santricity_smi-s_provider:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:tenable:log_correlation_engine:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus_network_monitor:5.11.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus_network_monitor:5.11.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus_network_monitor:5.12.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus_network_monitor:5.12.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:nessus_network_monitor:5.13.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:mcafee:web_gateway:8.2.19:*:*:*:*:*:*:*
Yes cpe:2.3:a:mcafee:web_gateway:9.2.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:mcafee:web_gateway:10.1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:mcafee:web_gateway_cloud_service:8.2.19:*:*:*:*:*:*:*
Yes cpe:2.3:a:mcafee:web_gateway_cloud_service:9.2.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:mcafee:web_gateway_cloud_service:10.1.1:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:checkpoint:quantum_security_management_firmware:r80.40:*:*:*:*:*:*:*
Yes cpe:2.3:o:checkpoint:quantum_security_management_firmware:r81:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:checkpoint:quantum_security_management:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:checkpoint:multi-domain_management_firmware:r80.40:*:*:*:*:*:*:*
Yes cpe:2.3:o:checkpoint:multi-domain_management_firmware:r81:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:checkpoint:multi-domain_management:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*
Yes cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:oracle:communications_communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:enterprise_manager_for_storage_management:13.4.0.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:essbase:21.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:graalvm:19.3.5:*:*:*:enterprise:*:*:*
Yes cpe:2.3:a:oracle:graalvm:20.3.1.2:*:*:*:enterprise:*:*:*
Yes cpe:2.3:a:oracle:graalvm:21.0.0.2:*:*:*:enterprise:*:*:*
Yes cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:mysql_connectors:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:secure_backup:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:sonicwall:sma100_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:sonicwall:sma100:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:sonicwall:capture_client:3.5:*:*:*:*:*:*:*
Yes cpe:2.3:o:sonicwall:sonicos:7.0.1.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:ruggedcom_rcm1224_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:ruggedcom_rcm1224:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_lpe9403_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_m-800_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_s602_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_s602:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_s612_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_s612:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_s623_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_s623:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_s627-2m_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_s627-2m:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_sc-600_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_sc-600:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_w700_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_w700:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_w1700_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_w1700:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xf-200ba_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xf-200ba:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xm-400:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xr-300wg_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xr-300wg:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xr524-8c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xr524-8c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xr526-8c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xr526-8c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xr528-6m_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xr528-6m:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_xr552-12_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_xr552-12:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_cloud_connect_7_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:siemens:simatic_cloud_connect_7_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_cloud_connect_7:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_cp_1242-7_gprs_v2_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:siemens:simatic_cp_1242-7_gprs_v2_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_cp_1242-7_gprs_v2:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_hmi_basic_panels_2nd_generation_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_hmi_basic_panels_2nd_generation:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_hmi_comfort_outdoor_panels:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_mv500_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_mv500:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp_1243-1_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp_1243-1:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp1243-7_lte_eu_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp1243-7_lte_eu:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp1243-7_lte_us_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp1243-7_lte_us:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp_1243-8_irc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp_1243-8_irc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_irc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp_1542sp-1_irc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp_1543-1:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp_1543sp-1_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp_1543sp-1:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_net_cp_1545-1:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_pcs_7_telecontrol_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_pcs_7_telecontrol:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_pcs_neo_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_pcs_neo:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_pdm_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_pdm:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_process_historian_opc_ua_server:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf166c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf166c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf185c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf185c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf186c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf186c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf186ci_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf186ci:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf188c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf188c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf188ci_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf188ci:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_rf360r_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_rf360r:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1211c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1211c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212fc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212fc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214_fc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214_fc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214_fc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214_fc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215_fc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215_fc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1200_cpu_1217c_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1200_cpu_1217c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:sinamics_connect_300_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:sinamics_connect_300:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:siemens:simatic_logon:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:simatic_logon:1.5:sp3_update_1:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:simatic_wincc_telecontrol:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinec_nms:1.0:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinec_nms:1.0:sp1:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinec_pni:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinema_server:14.0:-:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinema_server:14.0:sp1:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinema_server:14.0:sp2:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinema_server:14.0:sp2_update1:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinema_server:14.0:sp2_update2:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:sinumerik_opc_ua_server:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:siemens:tia_administrator:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

References

Notification
Message here