{"api_version":"1","generated_at":"2026-07-23T14:03:43+00:00","cve":"CVE-2021-44273","urls":{"html":"https://cve.report/CVE-2021-44273","api":"https://cve.report/api/cve/CVE-2021-44273.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-44273","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-44273"},"summary":{"title":"CVE-2021-44273","description":"e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-23 12:15:00","updated_at":"2023-09-13 00:15:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00010.html","name":"[debian-lts-announce] 20230912 [SECURITY] [DLA 3564-1] e2guardian security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3564-1] e2guardian security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2","name":"https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2","refsource":"MISC","tags":[],"title":"Fix bug #707 cert hostnames not being checked · e2guardian/e2guardian@eae46a7 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.openwall.com/lists/oss-security/2021/12/23/2","name":"[oss-security] 20211223 CVE-2021-44273: e2guardian did not validate TLS hostnames","refsource":"MLIST","tags":[],"title":"oss-security - CVE-2021-44273: e2guardian did not validate TLS hostnames","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/e2guardian/e2guardian/issues/707","name":"https://github.com/e2guardian/e2guardian/issues/707","refsource":"MISC","tags":[],"title":"v5.4: Missing SSL hostname check · Issue #707 · e2guardian/e2guardian · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-44273","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44273","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"44273","vulnerable":"1","versionEndIncluding":"5.4.3r","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"e2bn","cpe5":"e2guardian","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-44273","qid":"179424","title":"Debian Security Update for e2guardian (CVE-2021-44273)"},{"cve":"CVE-2021-44273","qid":"502559","title":"Alpine Linux Security Update for e2guardian"},{"cve":"CVE-2021-44273","qid":"504710","title":"Alpine Linux Security Update for e2guardian"},{"cve":"CVE-2021-44273","qid":"6000040","title":"Debian Security Update for e2guardian (DLA 3564-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-44273","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/e2guardian/e2guardian/issues/707","refsource":"MISC","name":"https://github.com/e2guardian/e2guardian/issues/707"},{"url":"https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2","refsource":"MISC","name":"https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2"},{"refsource":"MLIST","name":"[oss-security] 20211223 CVE-2021-44273: e2guardian did not validate TLS hostnames","url":"http://www.openwall.com/lists/oss-security/2021/12/23/2"},{"refsource":"MLIST","name":"[debian-lts-announce] 20230912 [SECURITY] [DLA 3564-1] e2guardian security update","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00010.html"}]}},"nvd":{"publishedDate":"2021-12-23 12:15:00","lastModifiedDate":"2023-09-13 00:15:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:e2bn:e2guardian:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.0","versionEndIncluding":"5.4.3r","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"44273","Ordinal":"222010","Title":"CVE-2021-44273","CVE":"CVE-2021-44273","Year":"2021"},"notes":[]}}}