VDB

SSA-772220

SSA-772220 PUBLISHED CVSS 5.900000095367432 MEDIUM

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensTIM 1531 IRC (6GK7543-1MX00-0XE0)
SiemensSIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0)
SiemensSIMATIC RF166C (6GT2002-0EE20)
SiemensSCALANCE SC632-2C (6GK5632-2GS00-2AC2)
SiemensSCALANCE S615 (6GK5615-0AA00-2AA2)
SiemensSIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0)
SiemensSIMATIC HMI Comfort Outdoor Panels (incl. SIPLUS variants)
SiemensSCALANCE XR-300WG
SiemensSIMATIC WinCC TeleControl
SiemensSIMATIC PCS neo
SiemensSIMATIC CP 1543-1 (6GK7543-1AX00-0XE0)
SiemensSCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0)
SiemensSINUMERIK OPC UA Server
SiemensSCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0)
SiemensSIMATIC RF650R (6GT2811-6AB20)
SiemensSIMATIC S7-1200 CPU family (incl. SIPLUS variants)
SiemensSIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0)
SiemensSCALANCE M874-2 (6GK5874-2AA00-2AA2)
SiemensSIMATIC MV550 S (6GF3550-0CD10)
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP family (incl. SIPLUS variant)

…and 75 more

Timeline

  • Jul 13, 2021 CVE Published
  • Jan 9, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›