CVE-2021-3618, known as ALPACA, is an application layer protocol content confusion attack affecting TLS servers that use compatible certificates for different protocols, such as multi-domain or wildcard certificates. A Man-in-the-Middle attacker can redirect traffic between subdomains, leading to valid but misdirected TLS sessions, potentially enabling cross-protocol attacks. This vulnerability has a CVSS score of 7.4 (HIGH) due to its network-based attack vector, high impact on confidentiality and integrity, and high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.21.0CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
< 8.17CPE matchmatch criteria | cpe:2.3:a:sendmail:sendmail:*:*:*:*:*:*:*:* | ||
< 3.0.4CPE matchmatch criteria | cpe:2.3:a:vsftpd_project:vsftpd:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-3618
Apr 12, 2022ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Mar 8, 2022ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
Jun 9, 2021