Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-3618
Description:ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2022.3888.1   1.3.6.1.4.1.25623.1.1.10.2021.0540   1.3.6.1.4.1.25623.1.1.4.2022.4192.1   1.3.6.1.4.1.25623.1.0.879807   1.3.6.1.4.1.25623.1.1.4.2022.3457.1   1.3.6.1.4.1.25623.1.0.822558   1.3.6.1.4.1.25623.1.1.12.2023.6379.1   1.3.6.1.4.1.25623.1.1.4.2022.3458.1   1.3.6.1.4.1.25623.1.0.845346   1.3.6.1.4.1.25623.1.1.4.2022.4265.1   1.3.6.1.4.1.25623.1.1.4.2022.3320.1   1.3.6.1.4.1.25623.1.1.4.2022.4266.1   1.3.6.1.4.1.25623.1.0.879805   1.3.6.1.4.1.25623.1.1.2.2021.2513   1.3.6.1.4.1.25623.1.1.4.2022.4201.1   1.3.6.1.4.1.25623.1.0.819016   1.3.6.1.4.1.25623.1.0.893203   1.3.6.1.4.1.25623.1.0.854998   1.3.6.1.4.1.25623.1.1.4.2022.3383.1   1.3.6.1.4.1.25623.1.0.819061  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-3618
https://alpaca-attack.com/
https://alpaca-attack.com/
https://bugzilla.redhat.com/show_bug.cgi?id=1975623
https://bugzilla.redhat.com/show_bug.cgi?id=1975623
https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html




© 1998-2025 E-Soft Inc. All rights reserved.