Vulnerability Name:

CVE-2021-3580 (CCN-204056)

Assigned:2021-06-04
Published:2021-06-04
Updated:2021-11-26
Summary:A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-3580

Source: CCN
Type: Red Hat Bugzilla - Bug 1967983
CVE-2021-3580 nettle: Remote crash in RSA decryption via manipulated ciphertext

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1967983

Source: XF
Type: UNKNOWN
gnunettle-cve20213580-dos(204056)

Source: CCN
Type: Nettle GIT Repository
Add input check to rsa_decrypt family of functions.

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210918 [SECURITY] [DLA 2760-1] nettle security update

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20211104-0006/

Source: CCN
Type: USN-4990-1
Nettle vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6560126 (Sterling Connect:Direct for UNIX Certified Container)
IBM Sterling Connect:Direct for UNIX Certified Container is affected by multiple vulnerabilities in Red Hat Universal Base Image version 8.4-206.1626828523 and Binutils version 2.30-93

Source: CCN
Type: IBM Security Bulletin 6574787 (QRadar SIEM)
IBM QRadar SIEM is vulnerable to using components with Known Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6589939 (MQ Operator)
IBM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from gzip, jackson-databind, libssh, gnutls, nettle and zlib

Source: CCN
Type: IBM Security Bulletin 6605839 (Security Verify Governance)
Multiple security vulnerabilities found in open source code that is shipped with IBM Security Verify Governance, Identity Manager virtual appliance component

Source: CCN
Type: IBM Security Bulletin 6854981 (Cloud Pak for Security)
IBM Cloud Pak for Security includes components with multiple known vulnerabilities

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nettle_project:nettle:*:*:*:*:*:*:*:* (Version < 3.7.3)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.3.3:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.3:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.10.6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7595
    P
    libhogweed6-3.8.1-150500.2.25 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:732
    P
    Security update for libostree (Important)
    2022-09-06
    oval:org.opensuse.security:def:3633
    P
    Security update for cifs-utils (Important)
    2022-07-13
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3010
    P
    apache2-2.4.23-29.43.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94560
    P
    ghostscript-9.52-161.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94640
    P
    libhogweed6-3.7.3-150400.2.21 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6070
    P
    Security update for the Linux Kernel (Important)
    2022-06-14
    oval:org.opensuse.security:def:95299
    P
    Security update for helm-mirror (Moderate)
    2022-05-31
    oval:org.opensuse.security:def:99490
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:102012
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 15 SP3) (Important)
    2022-03-01
    oval:org.opensuse.security:def:112646
    P
    libhogweed6-3.7.3-1.2 on GA media (Moderate)
    2022-01-17
    oval:com.redhat.rhsa:def:20214451
    P
    RHSA-2021:4451: gnutls and nettle security, bug fix, and enhancement update (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:99689
    P
    (Important)
    2021-10-26
    oval:org.opensuse.security:def:99997
    P
    (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:106127
    P
    libhogweed6-3.7.3-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:101273
    P
    jackson-databind-2.10.5.1-3.3.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:111600
    P
    Security update for libnettle (Important)
    2021-07-11
    oval:org.opensuse.security:def:111451
    P
    Security update for libnettle (Important)
    2021-06-24
    oval:org.opensuse.security:def:69495
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:31213
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:59500
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:88461
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:108678
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:55212
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:84169
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:127128
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:97133
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:10291
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:93091
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:8611
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:70431
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:99390
    P
    (Important)
    2021-06-23
    oval:org.opensuse.security:def:33677
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:64722
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:99099
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:29389
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:57469
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:86596
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:76227
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:82596
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:117454
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:9541
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:92540
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:100631
    P
    (Important)
    2021-06-23
    oval:org.opensuse.security:def:69681
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:31646
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:59758
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:89155
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:23612
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:55920
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:84628
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:73659
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:93244
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:42093
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:8793
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:91954
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:99653
    P
    (Important)
    2021-06-23
    oval:org.opensuse.security:def:33935
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:66840
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:99291
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:30097
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:57955
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:87418
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:51600
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:83304
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:125561
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:9740
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:92739
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:101463
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:5751
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:69880
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:32132
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:60295
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:89413
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:23928
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:56040
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:85677
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:73844
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:8988
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:92149
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:99967
    P
    (Important)
    2021-06-23
    oval:org.opensuse.security:def:34472
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:67159
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:30217
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:58777
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:88147
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:107939
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:51916
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:83424
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:126731
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:10109
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:92938
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:70249
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:32954
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:64537
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:98904
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:26080
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:57036
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:86110
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:75908
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:5067
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:9355
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:92341
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:100303
    P
    (Important)
    2021-06-23
    BACK
    nettle_project nettle *
    redhat enterprise linux 7.0
    redhat enterprise linux 8.0
    debian debian linux 9.0
    netapp ontap select deploy administration utility -
    ibm qradar security information and event manager 7.3.3
    ibm qradar security information and event manager 7.4.3 -
    ibm qradar security information and event manager 7.5.0 -
    ibm cloud pak for security 1.10.0.0
    ibm cloud pak for security 1.10.6.0