Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3449

57
FAUCET Score

CVE-2021-3449 is a denial-of-service vulnerability affecting OpenSSL TLS servers, including numerous products from vendors like Checkpoint, Debian, and Oracle. A maliciously crafted renegotiation ClientHello message can cause a server crash if it omits the signature_algorithms extension but includes signature_algorithms_cert. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high attack complexity, leading to a complete loss of availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.1, < 1.1.1kCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
12.2CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*
12.2CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
62.91%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.6291 is in the 99th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (39)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.40
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.5
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)Fixed in: 16.9.12
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)Fixed in: 16.7.20
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)Fixed in: 16.4.27
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-14.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_md-1:2.0.8-33.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-60.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-37.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1g-6.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-5.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1g-15.el8_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: openssl-1:1.1.1c-5.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: openssl-1:1.1.1c-18.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3.1Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat-native-0:1.2.23-24.redhat_24.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.4 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.25-4.redhat_4.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.4 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.25-4.redhat_4.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.5-20210330.0.el8_3
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-13.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBCS 2.4.37 SP7Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-70.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.14-20.Final_redhat_2.jbcs.el7
View patch
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 111.15.0
bentomlvendor investigatingvia llm_extracted
broadcomvendor investigatingvia llm_extracted
capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
honeywellvendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
phpofficevendor investigatingvia llm_extracted
pjsipvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted
typo3vendor investigatingvia llm_extracted

Vendor Advisories (15)

pjsipllm-pjsip-c99b20f90a5e04d2MEDIUM

Multiple vulnerabilities in MAP intrusion panel

Nov 19, 2025
typo3llm-typo3-6de19fc2ab7f8c50MEDIUM

Multiple vulnerabilities in MAP intrusion panel

Nov 19, 2025
phpofficellm-phpoffice-3e0fdb2e6e751ae3MEDIUM

Multiple vulnerabilities in MAP intrusion panel

Nov 19, 2025
broadcomllm-broadcom-47de3f565430384bMEDIUM

Multiple vulnerabilities in MAP intrusion panel

Nov 19, 2025
bentomlllm-bentoml-17a3f40fc718ff09MEDIUM

Multiple vulnerabilities in MAP intrusion panel

Nov 19, 2025
honeywellllm-honeywell-5010fa93a699ad1dMEDIUM

Multiple vulnerabilities in MAP intrusion panel

Nov 19, 2025
microsoft2021-Oct/CVE-2021-3449Important

OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing

Oct 12, 2021
rustGHSA-83mx-573x-5rw9medium

openssl-src NULL pointer Dereference in signature_algorithms processing

Aug 25, 2021
gcpllm-gcp-0e8476cc66fb0775CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
kongllm-kong-1666611432118a5eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
proxmoxllm-proxmox-2b2d17b42c53df6eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
capnprotollm-capnproto-2b74c0c7a557e2e2CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
hanwhallm-hanwha-1994c6c2f0952354CRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
openwrtllm-openwrt-653330e88153242eCRITICAL

ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities

Apr 30, 2021
redhatCVE-2021-3449Important

openssl: NULL pointer dereference in signature_algorithms processing

Mar 25, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-389290.pdf
Third Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-772220.pdf
PatchThird Party Advisory
git.openssl.org / gitweb
kb.pulsesecure.net / articles/Pulse_Security_Advisories/SA44845
Third Party Advisory
kc.mcafee.com / corporate/index
Third Party Advisory
lists.debian.org / debian-lts-announce/2021/08/msg00029.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP
psirt.global.sonicwall.com / vuln-detail/SNWLID-2021-0013
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-21:07.openssl.asc
Third Party Advisory
security.gentoo.org / glsa/202103-03
Third Party Advisory
security.netapp.com / advisory/ntap-20210326-0006
Third Party Advisory
security.netapp.com / advisory/ntap-20210513-0002
Third Party Advisory
security.netapp.com / advisory/ntap-20240621-0006
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
Third Party Advisory
debian.org / security/2021/dsa-4875
Third Party Advisory
openssl.org / news/secadv/20210325.txt
Vendor Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
Third Party Advisory
oracle.com / security-alerts/cpuoct2021.html
Third Party Advisory
tenable.com / security/tns-2021-05
Third Party Advisory
tenable.com / security/tns-2021-06
Third Party Advisory
tenable.com / security/tns-2021-09
Third Party Advisory
tenable.com / security/tns-2021-10
Third Party Advisory
openwall.com / lists/oss-security/2021/03/27/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/03/27/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/03/28/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/03/28/4
Mailing ListThird Party Advisory