CVE-2021-22924
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD
Description
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Affected (40)
Show all products
Haxx: Libcurl · Fedoraproject: Fedora · Debian: Debian Linux · Netapp: Cloud Backup, Clustered Data Ontap, Solidfire & Hci Management Node, Solidfire Baseboard Management Controller Firmware · Oracle: Mysql Server, Peoplesoft Enterprise Peopletools · Siemens: Sinec Infrastructure Network Services, Sinema Remote Connect Server, Logo! Cmr2040 Firmware, Logo! Cmr2020 Firmware, Ruggedcomrm 1224 Lte Firmware, Scalance M804pb Firmware, Scalance M812 1 Firmware, Scalance M816 1 Firmware, Scalance M826 2 Firmware, Scalance M874 2 Firmware, Scalance M874 3 Firmware, Scalance M876 3 Firmware, Scalance M876 4 Firmware, Scalance Mum856 1 Firmware, Scalance S615 Firmware, Simatic Cp 1543 1 Firmware, Simatic Cp 1545 1 Firmware, Simatic Rtu3010c Firmware, Simatic Rtu3030c Firmware, Simatic Rtu3031c Firmware, Simatic Rtu 3041c Firmware, Sinema Remote Connect, Siplus Net Cp 1543 1 Firmware · Splunk: Universal Forwarder
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.7.0 to 5.7.36 | |
| Version 8.57 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.1 | |
| Before 3.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Logo! Cmr2040 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Logo! Cmr2020 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcomrm 1224 Lte | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M804pb | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M812 1 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M816 1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M826 2 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M874 2 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M874 3 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M876 3 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M876 4 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Mum856 1 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance S615 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.22 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1543 1 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1545 1 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rtu3010c | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rtu3030c | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rtu3031c | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.0.14 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rtu 3041c | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.1 |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.22 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Net Cp 1543 1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.2.0 to 8.2.12 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-706
Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
References (30)
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
ExploitIssue TrackingPatchThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.