PT-2021-5840 · Nginx+8 · Nginx+8
Huzaifa S. Sidhpurwala
·
Published
2021-06-24
·
Updated
2026-03-10
·
CVE-2021-3618
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
vsftpd (affected versions not specified)
Sendmail (affected versions not specified)
Nginx (affected versions not specified)
Description
The issue is related to an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Recommendations
For vsftpd, consider implementing additional security measures to protect against MiTM attacks, such as encrypting data in transit.
For Sendmail, as a temporary workaround, consider disabling the use of multi-domain or wildcard certificates until a patch is available.
For Nginx, restrict access to sensitive areas of the web server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Nginx
Red Os
Sendmail
Suse
Ubuntu