CVE Vulnerabilities

CVE-2021-3618

Improper Certificate Validation

Published: Mar 23, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victims traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
NginxF5*1.21.0 (excluding)
NginxUbuntubionic*
NginxUbuntuesm-infra-legacy/trusty*
NginxUbuntuesm-infra/bionic*
NginxUbuntuesm-infra/focal*
NginxUbuntuesm-infra/xenial*
NginxUbuntufocal*
NginxUbuntuhirsute*
NginxUbuntuimpish*
NginxUbuntujammy*
NginxUbuntukinetic*
NginxUbuntutrusty*
NginxUbuntutrusty/esm*
NginxUbuntuupstream*
NginxUbuntuxenial*
SendmailUbuntubionic*
SendmailUbuntuesm-apps/bionic*
SendmailUbuntuesm-apps/focal*
SendmailUbuntuesm-apps/jammy*
SendmailUbuntuesm-infra-legacy/trusty*
SendmailUbuntufocal*
SendmailUbuntuhirsute*
SendmailUbuntuimpish*
SendmailUbuntujammy*
SendmailUbuntukinetic*
SendmailUbuntutrusty*
SendmailUbuntutrusty/esm*
SendmailUbuntuupstream*
SendmailUbuntuxenial*
VsftpdUbuntubionic*
VsftpdUbuntuesm-infra-legacy/trusty*
VsftpdUbuntuesm-infra/bionic*
VsftpdUbuntuesm-infra/focal*
VsftpdUbuntuesm-infra/xenial*
VsftpdUbuntufocal*
VsftpdUbuntuhirsute*
VsftpdUbuntuimpish*
VsftpdUbuntutrusty*
VsftpdUbuntutrusty/esm*
VsftpdUbuntuupstream*
VsftpdUbuntuxenial*

Potential Mitigations

References