Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23841

24
FAUCET Score

CVE-2021-23841 is a medium-severity denial-of-service vulnerability in OpenSSL versions 1.1.1i and below, as well as 1.0.2x and below. It arises from improper error handling in the X509_issuer_and_serial_hash() function when processing maliciously constructed X.509 certificate issuer fields, leading to a NULL pointer dereference and application crash. This vulnerability primarily impacts applications that directly use this specific OpenSSL function on untrusted certificates. The vulnerability has a CVSS score of 5.9, indicating a medium severity. An unauthenticated attacker can trigger this vulnerability over the network with high attack complexity, resulting in a denial-of-service impact. There is no impact on confidentiality or integrity. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low current attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.0.2yCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.1, < 1.1.1jCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
5.11.0CPE matchmatch criteria
cpe:2.3:a:tenable:nessus_network_monitor:5.11.0:*:*:*:*:*:*:*
5.11.1CPE matchmatch criteria
cpe:2.3:a:tenable:nessus_network_monitor:5.11.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.47%
Probability of exploitation in next 30 days
EPSS Percentile
93.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0747 is in the 93rd percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (53)

microsoftpatch availablevia msrc
Product: azl3 shim-unsigned-x64 15.8-5 on Azure Linux 3.0Fixed in: 15.8-5
microsoftpatch availablevia msrc
Product: 17013-17084Fixed in: 15.8-5
microsoftpatch availablevia msrc
Product: 17012-17084Fixed in: 15.8-5
microsoftpatch availablevia msrc
Product: azl3 shim-unsigned-aarch64 15.8-5 on Azure Linux 3.0Fixed in: 15.8-5
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.16-9.Final_redhat_2.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-21.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-20.redhat_1.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_md-1:2.0.8-40.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_security-0:2.9.2-67.GA.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-39.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-1:1.1.1g-8.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-7.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-22.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-107.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-84.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:7.78.0-2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-78.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.16-9.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-21.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-20.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_md-1:2.0.8-40.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-67.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-39.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1g-8.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-7.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-22.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.2k-22.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: edk2-0:20210527gite1999b264f1f-3.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1k-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 7Fixed in: jws5-tomcat-0:9.0.50-3.redhat_00004.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.30-3.redhat_3.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 7Fixed in: jws5-tomcat-vault-0:1.1.8-4.Final_redhat_00004.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 8Fixed in: jws5-tomcat-0:9.0.50-3.redhat_00004.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.30-3.redhat_3.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 8Fixed in: jws5-tomcat-vault-0:1.1.8-4.Final_redhat_00004.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: jbcs-httpd24-openssl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-apr-0:1.6.3-107.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-apr-util-0:1.6.1-84.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-curl-0:7.78.0-2.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-httpd-0:2.4.37-78.el8jbcs
View patch
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 111.14.0
capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ovmf
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: management-ingress
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: compat-openssl10
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl098e

Vendor Advisories (9)

rustGHSA-84rm-qf37-fgc2medium

Integer Overflow in openssl-src

Aug 25, 2021
proxmoxllm-proxmox-2b2d17b42c53df6eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
kongllm-kong-1666611432118a5eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
hanwhallm-hanwha-1994c6c2f0952354CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
capnprotollm-capnproto-2b74c0c7a557e2e2CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
openwrtllm-openwrt-653330e88153242eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
gcpllm-gcp-0e8476cc66fb0775CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
redhatCVE-2021-23841Moderate

openssl: NULL pointer dereference in X509_issuer_and_serial_hash()

Feb 16, 2021
microsoft2021-Feb/CVE-2021-23841Moderate

Null pointer deref in X509_issuer_and_serial_hash()

Feb 9, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-637483.pdf
PatchThird Party Advisory
seclists.org / fulldisclosure/2021/May/67
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2021/May/68
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2021/May/70
Mailing ListThird Party Advisory
git.openssl.org / gitweb
git.openssl.org / gitweb
kb.pulsesecure.net / articles/Pulse_Security_Advisories/SA44846
Third Party Advisory
security.gentoo.org / glsa/202103-03
Third Party Advisory
security.netapp.com / advisory/ntap-20210219-0009
Third Party Advisory
security.netapp.com / advisory/ntap-20210513-0002
Third Party Advisory
security.netapp.com / advisory/ntap-20240621-0006
support.apple.com / kb/HT212528
Third Party Advisory
support.apple.com / kb/HT212529
Third Party Advisory
support.apple.com / kb/HT212534
Third Party Advisory
debian.org / security/2021/dsa-4855
Third Party Advisory
openssl.org / news/secadv/20210216.txt
Vendor Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory
tenable.com / security/tns-2021-03
Third Party Advisory
tenable.com / security/tns-2021-09
Third Party Advisory