---
id: CVE-2021-3449
title: >-
  An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation
  ClientHello message from a client
summary: >-
  An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation
  ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello
  omits the signature_algorithms extension (where it was present in the initial
  ClientHel…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: openssl
product: openssl
affected:
  - 'openssl >= 1.1.1, < 1.1.1k'
  - debian_linux = 9.0
  - debian_linux = 10.0
  - freebsd = 12.2
  - active_iq_unified_manager
  - cloud_volumes_ontap_mediator
  - e-series_performance_analyzer
  - oncommand_insight
  - oncommand_workflow_automation
  - ontap_select_deploy_administration_utility
  - santricity_smi-s_provider
  - snapcenter
  - storagegrid
  - log_correlation_engine < 6.0.9
  - nessus <= 8.13.1
  - nessus_network_monitor = 5.11.0
  - nessus_network_monitor = 5.11.1
  - nessus_network_monitor = 5.12.0
  - nessus_network_monitor = 5.12.1
  - nessus_network_monitor = 5.13.0
  - 'tenable.sc >= 5.13.0, <= 5.17.0'
  - fedora = 34
  - web_gateway = 8.2.19
  - web_gateway = 9.2.10
  - web_gateway = 10.1.1
  - web_gateway_cloud_service = 8.2.19
  - web_gateway_cloud_service = 9.2.10
  - web_gateway_cloud_service = 10.1.1
  - quantum_security_management_firmware = r80.40
  - quantum_security_management_firmware = r81
  - multi-domain_management_firmware = r80.40
  - multi-domain_management_firmware = r81
  - quantum_security_gateway_firmware = r80.40
  - quantum_security_gateway_firmware = r81
  - communications_communications_policy_management = 12.6.0.0.0
  - enterprise_manager_for_storage_management = 13.4.0.0
  - essbase = 21.2
  - graalvm = 19.3.5
  - graalvm = 20.3.1.2
  - graalvm = 21.0.0.2
  - jd_edwards_enterpriseone_tools < 9.2.6.0
  - jd_edwards_world_security = a9.4
  - mysql_connectors <= 8.0.23
  - mysql_server <= 5.7.33
  - 'mysql_server >= 8.0.15, <= 8.0.23'
  - mysql_workbench <= 8.0.23
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - 'primavera_unifier >= 17.7, <= 17.12'
  - primavera_unifier = 19.12
  - primavera_unifier = 20.12
  - primavera_unifier = 21.12
  - secure_backup < 18.1.0.1.0
  - secure_global_desktop = 5.6
  - zfs_storage_appliance_kit = 8.8
  - 'sma100_firmware >= 10.2.0.0, < 10.2.1.0-17sv'
  - capture_client = 3.5
  - sonicos = 7.0.1.0
  - ruggedcom_rcm1224_firmware >= 6.2
  - scalance_lpe9403_firmware
  - scalance_m-800_firmware >= 6.2
  - scalance_s602_firmware >= 4.1
  - scalance_s612_firmware >= 4.1
  - scalance_s615_firmware >= 6.2
  - scalance_s623_firmware >= 4.1
  - scalance_s627-2m_firmware >= 4.1
  - scalance_sc-600_firmware >= 2.0
  - scalance_w700_firmware >= 6.5
  - scalance_w1700_firmware >= 2.0
  - scalance_xb-200_firmware < 4.3
  - scalance_xc-200_firmware < 4.3
  - scalance_xf-200ba_firmware < 4.3
  - scalance_xm-400_firmware < 6.4
  - scalance_xp-200_firmware < 4.3
  - scalance_xr-300wg_firmware < 4.3
  - scalance_xr524-8c_firmware < 6.4
  - scalance_xr526-8c_firmware < 6.4
  - scalance_xr528-6m_firmware < 6.4
  - scalance_xr552-12_firmware < 6.4
  - simatic_cloud_connect_7_firmware >= 1.1
  - simatic_cloud_connect_7_firmware
  - simatic_cp_1242-7_gprs_v2_firmware >= 3.1
  - simatic_cp_1242-7_gprs_v2_firmware
  - simatic_hmi_basic_panels_2nd_generation_firmware
  - simatic_hmi_comfort_outdoor_panels_firmware
  - simatic_hmi_ktp_mobile_panels_firmware
  - simatic_mv500_firmware
  - simatic_net_cp_1243-1_firmware >= 3.1
  - simatic_net_cp1243-7_lte_eu_firmware >= 3.1
  - simatic_net_cp1243-7_lte_us_firmware >= 3.1
  - simatic_net_cp_1243-8_irc_firmware >= 3.1
  - simatic_net_cp_1542sp-1_irc_firmware >= 2.1
  - 'simatic_net_cp_1543-1_firmware >= 2.2, < 3.0'
  - simatic_net_cp_1543sp-1_firmware >= 2.1
  - simatic_net_cp_1545-1_firmware >= 1.0
  - simatic_pcs_7_telecontrol_firmware
  - simatic_pcs_neo_firmware
  - simatic_pdm_firmware >= 9.1.0.7
  - simatic_process_historian_opc_ua_server_firmware >= 2019
patched:
  - openssl 1.1.1k
  - log_correlation_engine 6.0.9
  - jd_edwards_enterpriseone_tools 9.2.6.0
  - secure_backup 18.1.0.1.0
  - sma100_firmware 10.2.1.0-17sv
  - scalance_xb-200_firmware 4.3
  - scalance_xc-200_firmware 4.3
  - scalance_xf-200ba_firmware 4.3
  - scalance_xm-400_firmware 6.4
  - scalance_xp-200_firmware 4.3
  - scalance_xr-300wg_firmware 4.3
  - scalance_xr524-8c_firmware 6.4
  - scalance_xr526-8c_firmware 6.4
  - scalance_xr528-6m_firmware 6.4
  - scalance_xr552-12_firmware 6.4
  - simatic_net_cp_1543-1_firmware 3.0
published: '2021-03-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:11.243'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-3449'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/27/1'
    label: openssl-security@openssl.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/27/2'
    label: openssl-security@openssl.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/28/3'
    label: openssl-security@openssl.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/28/4'
    label: openssl-security@openssl.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf'
    label: openssl-security@openssl.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf'
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148
    label: openssl-security@openssl.org
  - url: 'https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845'
    label: openssl-security@openssl.org
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10356'
    label: openssl-security@openssl.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html'
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/
    label: openssl-security@openssl.org
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013'
    label: openssl-security@openssl.org
  - url: 'https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc'
    label: openssl-security@openssl.org
  - url: 'https://security.gentoo.org/glsa/202103-03'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20210326-0006/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20210513-0002/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20240621-0006/'
    label: openssl-security@openssl.org
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
    label: openssl-security@openssl.org
  - url: 'https://www.debian.org/security/2021/dsa-4875'
    label: openssl-security@openssl.org
  - url: 'https://www.openssl.org/news/secadv/20210325.txt'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2021-05'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2021-06'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2021-09'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2021-10'
    label: openssl-security@openssl.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/27/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/27/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/28/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/28/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10356'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202103-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210326-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210513-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20240621-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-4875'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openssl.org/news/secadv/20210325.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2021-05'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2021-06'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2021-09'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2021-10'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.63542
epssPercentile: 0.99195
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/riptl/cve-2021-3449'
  checkedAt: '2026-10-08T23:17:21.750Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.316Z'
---

## Overview

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

## Affected

- `openssl >= 1.1.1, < 1.1.1k`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `freebsd = 12.2`
- `active_iq_unified_manager`
- `cloud_volumes_ontap_mediator`
- `e-series_performance_analyzer`
- `oncommand_insight`
- `oncommand_workflow_automation`
- `ontap_select_deploy_administration_utility`
- `santricity_smi-s_provider`
- `snapcenter`
- `storagegrid`
- `log_correlation_engine < 6.0.9`
- `nessus <= 8.13.1`
- `nessus_network_monitor = 5.11.0`
- `nessus_network_monitor = 5.11.1`
- `nessus_network_monitor = 5.12.0`
- `nessus_network_monitor = 5.12.1`
- `nessus_network_monitor = 5.13.0`
- `tenable.sc >= 5.13.0, <= 5.17.0`
- `fedora = 34`
- `web_gateway = 8.2.19`
- `web_gateway = 9.2.10`
- `web_gateway = 10.1.1`
- `web_gateway_cloud_service = 8.2.19`
- `web_gateway_cloud_service = 9.2.10`
- `web_gateway_cloud_service = 10.1.1`
- `quantum_security_management_firmware = r80.40`
- `quantum_security_management_firmware = r81`
- `multi-domain_management_firmware = r80.40`
- `multi-domain_management_firmware = r81`
- `quantum_security_gateway_firmware = r80.40`
- `quantum_security_gateway_firmware = r81`
- `communications_communications_policy_management = 12.6.0.0.0`
- `enterprise_manager_for_storage_management = 13.4.0.0`
- `essbase = 21.2`
- `graalvm = 19.3.5`
- `graalvm = 20.3.1.2`
- `graalvm = 21.0.0.2`
- `jd_edwards_enterpriseone_tools < 9.2.6.0`
- `jd_edwards_world_security = a9.4`
- `mysql_connectors <= 8.0.23`
- `mysql_server <= 5.7.33`
- `mysql_server >= 8.0.15, <= 8.0.23`
- `mysql_workbench <= 8.0.23`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `primavera_unifier >= 17.7, <= 17.12`
- `primavera_unifier = 19.12`
- `primavera_unifier = 20.12`
- `primavera_unifier = 21.12`
- `secure_backup < 18.1.0.1.0`
- `secure_global_desktop = 5.6`
- `zfs_storage_appliance_kit = 8.8`
- `sma100_firmware >= 10.2.0.0, < 10.2.1.0-17sv`
- `capture_client = 3.5`
- `sonicos = 7.0.1.0`
- `ruggedcom_rcm1224_firmware >= 6.2`
- `scalance_lpe9403_firmware`
- `scalance_m-800_firmware >= 6.2`
- `scalance_s602_firmware >= 4.1`
- `scalance_s612_firmware >= 4.1`
- `scalance_s615_firmware >= 6.2`
- `scalance_s623_firmware >= 4.1`
- `scalance_s627-2m_firmware >= 4.1`
- `scalance_sc-600_firmware >= 2.0`
- `scalance_w700_firmware >= 6.5`
- `scalance_w1700_firmware >= 2.0`
- `scalance_xb-200_firmware < 4.3`
- `scalance_xc-200_firmware < 4.3`
- `scalance_xf-200ba_firmware < 4.3`
- `scalance_xm-400_firmware < 6.4`
- `scalance_xp-200_firmware < 4.3`
- `scalance_xr-300wg_firmware < 4.3`
- `scalance_xr524-8c_firmware < 6.4`
- `scalance_xr526-8c_firmware < 6.4`
- `scalance_xr528-6m_firmware < 6.4`
- `scalance_xr552-12_firmware < 6.4`
- `simatic_cloud_connect_7_firmware >= 1.1`
- `simatic_cloud_connect_7_firmware`
- `simatic_cp_1242-7_gprs_v2_firmware >= 3.1`
- `simatic_cp_1242-7_gprs_v2_firmware`
- `simatic_hmi_basic_panels_2nd_generation_firmware`
- `simatic_hmi_comfort_outdoor_panels_firmware`
- `simatic_hmi_ktp_mobile_panels_firmware`
- `simatic_mv500_firmware`
- `simatic_net_cp_1243-1_firmware >= 3.1`
- `simatic_net_cp1243-7_lte_eu_firmware >= 3.1`
- `simatic_net_cp1243-7_lte_us_firmware >= 3.1`
- `simatic_net_cp_1243-8_irc_firmware >= 3.1`
- `simatic_net_cp_1542sp-1_irc_firmware >= 2.1`
- `simatic_net_cp_1543-1_firmware >= 2.2, < 3.0`
- `simatic_net_cp_1543sp-1_firmware >= 2.1`
- `simatic_net_cp_1545-1_firmware >= 1.0`
- `simatic_pcs_7_telecontrol_firmware`
- `simatic_pcs_neo_firmware`
- `simatic_pdm_firmware >= 9.1.0.7`
- `simatic_process_historian_opc_ua_server_firmware >= 2019`

## Remediation

Upgrade past the affected range:

- `openssl 1.1.1k`
- `log_correlation_engine 6.0.9`
- `jd_edwards_enterpriseone_tools 9.2.6.0`
- `secure_backup 18.1.0.1.0`
- `sma100_firmware 10.2.1.0-17sv`
- `scalance_xb-200_firmware 4.3`
- `scalance_xc-200_firmware 4.3`
- `scalance_xf-200ba_firmware 4.3`
- `scalance_xm-400_firmware 6.4`
- `scalance_xp-200_firmware 4.3`
- `scalance_xr-300wg_firmware 4.3`
- `scalance_xr524-8c_firmware 6.4`
- `scalance_xr526-8c_firmware 6.4`
- `scalance_xr528-6m_firmware 6.4`
- `scalance_xr552-12_firmware 6.4`
- `simatic_net_cp_1543-1_firmware 3.0`
