| Vulnerability Name: | CVE-2021-3446 (CCN-198803) | ||||||||||||||||||||||||||||||||
| Assigned: | 2021-03-16 | ||||||||||||||||||||||||||||||||
| Published: | 2021-03-16 | ||||||||||||||||||||||||||||||||
| Updated: | 2022-10-27 | ||||||||||||||||||||||||||||||||
| Summary: | A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality. | ||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C) 
 5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C) 
 | ||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 
 
 | ||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-330 | ||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-3446 Source: CCN Type: Red Hat Bugzilla - Bug 1939664 CVE-2021-3446 libtpms: return of wrong initialization vector when certain symmetric ciphers are used Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1939664 Source: XF Type: UNKNOWN libtpms-cve20213446-info-disc(198803) Source: CCN Type: libtpms GIT Repository tpm2: CryptSym: fix AES output IV Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-3446 | ||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1:  Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||