PT-2021-5840 · Nginx+8 · Nginx+8

Huzaifa S. Sidhpurwala

·

Published

2021-06-24

·

Updated

2026-03-10

·

CVE-2021-3618

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions vsftpd (affected versions not specified) Sendmail (affected versions not specified) Nginx (affected versions not specified)
Description The issue is related to an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Recommendations For vsftpd, consider implementing additional security measures to protect against MiTM attacks, such as encrypting data in transit. For Sendmail, as a temporary workaround, consider disabling the use of multi-domain or wildcard certificates until a patch is available. For Nginx, restrict access to sensitive areas of the web server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2224
ALT-PU-2022-2243
ALT-PU-2022-2253
ALT-PU-2022-2267
ALT-PU-2023-5845
ALT-PU-2024-10932
ALT-PU-2024-15710
ALT-PU-2024-15763
AZL-9188
AZL-9190
AZL-9220
BDU:2022-00351
BIT-NGINX-2021-3618
BIT-NGINX-GATEWAY-2021-3618
CVE-2021-3618
DLA-3203-1
MGASA-2021-0540
OESA-2022-1637
OPENSUSE-SU-2022_3320-1
OPENSUSE-SU-2022_3457-1
OPENSUSE-SU-2022_4201-1
ROSA-SA-2023-2269
ROSA-SA-2025-2895
SUSE-RU-2022:0655-1
SUSE-SU-2022:3320-1
SUSE-SU-2022:3383-1
SUSE-SU-2022:3457-1
SUSE-SU-2022:3458-1
SUSE-SU-2022:3888-1
SUSE-SU-2022:4192-1
SUSE-SU-2022:4201-1
SUSE-SU-2022:4265-1
SUSE-SU-2022:4266-1
SUSE-SU-2022_3320-1
SUSE-SU-2022_3383-1
SUSE-SU-2022_3457-1
SUSE-SU-2022_3458-1
SUSE-SU-2022_3888-1
SUSE-SU-2022_4192-1
SUSE-SU-2022_4201-1
SUSE-SU-2022_4265-1
SUSE-SU-2022_4266-1
USN-5371-1
USN-5371-2
USN-6379-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Nginx
Red Os
Sendmail
Suse
Ubuntu