CVE-2021-4044 is a high-severity vulnerability in OpenSSL 3.0.0, specifically within its libssl component, affecting products like NetApp and Node.js. It involves a mishandling of negative return values from the X509_verify_cert() function during server certificate verification, leading to unexpected SSL_ERROR_WANT_RETRY_VERIFY errors. This can cause application crashes, infinite loops, or other incorrect behaviors, particularly when combined with another OpenSSL 3.0 bug related to certificate chains and name constraints. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and no user interaction required, potentially leading to high availability impact. Its FAUCET Risk Score is 85/100, and its EPSS score suggests a higher-than-average likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:3.0.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.