CVE Feed

    Dashboard / CVE / CVE-2021-22924

    CVE-2021-22924

    libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.

    Published:Jul 21, 2021
    Last Modified:Jun 9, 2025
    EPS:Aug 5, 2021
    EPSS Score:0.0063
    CVSS Score:3.7

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Haxx
    Product
    Libcurl
    Vendor
    Netapp
    Product
    Cloud Backup
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Solidfire \& Hci Management Node
    Vendor
    Netapp
    Product
    Solidfire Baseboard Management Controller Firmware
    Vendor
    Oracle
    Product
    Mysql Server
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Rhel Dotnet
    Vendor
    Siemens
    Product
    Logo\! Cmr2020
    Vendor
    Siemens
    Product
    Logo\! Cmr2020 Firmware
    Vendor
    Siemens
    Product
    Logo\! Cmr2040
    Vendor
    Siemens
    Product
    Logo\! Cmr2040 Firmware
    Vendor
    Siemens
    Product
    Ruggedcomrm 1224 Lte
    Vendor
    Siemens
    Product
    Ruggedcomrm 1224 Lte Firmware
    Vendor
    Siemens
    Product
    Scalance M804pb
    Vendor
    Siemens
    Product
    Scalance M804pb Firmware
    Vendor
    Siemens
    Product
    Scalance M812-1
    Vendor
    Siemens
    Product
    Scalance M812-1 Firmware
    Vendor
    Siemens
    Product
    Scalance M816-1
    Vendor
    Siemens
    Product
    Scalance M816-1 Firmware
    Vendor
    Siemens
    Product
    Scalance M826-2
    Vendor
    Siemens
    Product
    Scalance M826-2 Firmware
    Vendor
    Siemens
    Product
    Scalance M874-2
    Vendor
    Siemens
    Product
    Scalance M874-2 Firmware
    Vendor
    Siemens
    Product
    Scalance M874-3
    Vendor
    Siemens
    Product
    Scalance M874-3 Firmware
    Vendor
    Siemens
    Product
    Scalance M876-3
    Vendor
    Siemens
    Product
    Scalance M876-3 Firmware
    Vendor
    Siemens
    Product
    Scalance M876-4
    Vendor
    Siemens
    Product
    Scalance M876-4 Firmware
    Vendor
    Siemens
    Product
    Scalance Mum856-1
    Vendor
    Siemens
    Product
    Scalance Mum856-1 Firmware
    Vendor
    Siemens
    Product
    Scalance S615
    Vendor
    Siemens
    Product
    Scalance S615 Firmware
    Vendor
    Siemens
    Product
    Simatic Cp 1543-1
    Vendor
    Siemens
    Product
    Simatic Cp 1543-1 Firmware
    Vendor
    Siemens
    Product
    Simatic Cp 1545-1
    Vendor
    Siemens
    Product
    Simatic Cp 1545-1 Firmware
    Vendor
    Siemens
    Product
    Simatic Rtu3010c
    Vendor
    Siemens
    Product
    Simatic Rtu3010c Firmware
    Vendor
    Siemens
    Product
    Simatic Rtu3030c
    Vendor
    Siemens
    Product
    Simatic Rtu3030c Firmware
    Vendor
    Siemens
    Product
    Simatic Rtu3031c
    Vendor
    Siemens
    Product
    Simatic Rtu3031c Firmware
    Vendor
    Siemens
    Product
    Simatic Rtu 3041c
    Vendor
    Siemens
    Product
    Simatic Rtu 3041c Firmware
    Vendor
    Siemens
    Product
    Sinec Infrastructure Network Services
    Vendor
    Siemens
    Product
    Sinema Remote Connect
    Vendor
    Siemens
    Product
    Sinema Remote Connect Server
    Vendor
    Siemens
    Product
    Siplus Net Cp 1543-1
    Vendor
    Siemens
    Product
    Siplus Net Cp 1543-1 Firmware
    Vendor
    Splunk
    Product
    Universal Forwarder

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High