← Back

CVE-2021-3618

nvd nist
Published: Mar 23, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

Affected (7)

Products: F5: Nginx · Sendmail: Sendmail · Vsftpd Project: Vsftpd · +2 more
Show all products
1 product
Nginx
1 product
Sendmail
Vsftpd
1 product
Fedora
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.21.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.17
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.0.4
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Version 35
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (6)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.