CVE-2021-3449 is a denial-of-service vulnerability affecting OpenSSL TLS servers, including numerous products from vendors like Checkpoint, Debian, and Oracle. A maliciously crafted renegotiation ClientHello message can cause a server crash if it omits the signature_algorithms extension but includes signature_algorithms_cert. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high attack complexity, leading to a complete loss of availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.1, < 1.1.1kCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities in MAP intrusion panel
Nov 19, 2025Multiple vulnerabilities in MAP intrusion panel
Nov 19, 2025Multiple vulnerabilities in MAP intrusion panel
Nov 19, 2025Multiple vulnerabilities in MAP intrusion panel
Nov 19, 2025Multiple vulnerabilities in MAP intrusion panel
Nov 19, 2025Multiple vulnerabilities in MAP intrusion panel
Nov 19, 2025OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing
Oct 12, 2021openssl-src NULL pointer Dereference in signature_algorithms processing
Aug 25, 2021ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
Apr 30, 2021ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
Apr 30, 2021ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
Apr 30, 2021ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
Apr 30, 2021ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
Apr 30, 2021ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
Apr 30, 2021openssl: NULL pointer dereference in signature_algorithms processing
Mar 25, 2021