CVE-2021-3449: Check Point Multi-Domain Management Firmware

Medium severity, CVSS 5.9. EPSS: 63.5% chance of exploitation in the next 30 days.

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Affected products

  • Check Point Multi-Domain Management Firmware: version r80.40 only; version r81 only
  • Check Point Quantum Security Gateway Firmware: version r80.40 only; version r81 only
  • Check Point Quantum Security Management Firmware: version r80.40 only; version r81 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 34 only
  • Freebsd Freebsd: version 12.2 only
  • McAfee Web Gateway: version 8.2.19 only; version 9.2.10 only; version 10.1.1 only
  • McAfee Web Gateway Cloud Service: version 8.2.19 only; version 9.2.10 only; version 10.1.1 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Cloud Volumes Ontap Mediator: affected versions not specified
  • Netapp E-Series Performance Analyzer: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Santricity Smi-S Provider: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Storagegrid: affected versions not specified
  • Node.js Node.js: from 10.0.0, up to and including 10.12.0; from 10.13.0, up to and including 10.24.0; from 12.0.0, up to and including 12.12.0; from 12.13.0, before 12.22.1 (fixed in 12.22.1); from 14.0.0, up to and including 14.14.0; from 14.15.0, before 14.16.1 (fixed in 14.16.1); …
  • OpenSSL OpenSSL: from 1.1.1, before 1.1.1k (fixed in 1.1.1k)
  • Oracle Communications Communications Policy Management: version 12.6.0.0.0 only
  • Oracle Enterprise Manager For Storage Management: version 13.4.0.0 only
  • Oracle Essbase: version 21.2 only
  • Oracle Graalvm: version 19.3.5 only; version 20.3.1.2 only; version 21.0.0.2 only
  • Oracle Jd Edwards Enterpriseone Tools: before 9.2.6.0 (fixed in 9.2.6.0)
  • Oracle Jd Edwards World Security: version a9.4 only
  • and 81 more

Published 2021-03-25. Last modified 2026-10-08.