CVE-2021-22946Patch(apple / cloud_backup)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple cloud_backup systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-325CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_backup
  • clustered_data_ontap
  • commerce_guided_search
  • communications_cloud_native_core_binding_support_function

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
cloud_backupclustered_data_ontapcommerce_guided_searchcommunications_cloud_native_core_binding_support_functioncommunications_cloud_native_core_consolecommunications_cloud_native_core_network_function_cloud_native_environmentcommunications_cloud_native_core_network_repository_functioncommunications_cloud_native_core_network_slice_selection_functioncommunications_cloud_native_core_security_edge_protection_proxycommunications_cloud_native_core_service_communication_proxy

20 versions affected across 37 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-24: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-24: 104-24
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2021-22946 (CVSS 7.5) curl 7.20.0-7.78.0 TLS upgrade bypass in IMAP/POP3/FTP. Attackers can force cleartext transmission of sensitive data despite --ssl-reqd flag. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/TMKJlN0oEX

    Post summary

    The tweet announces CVE-2021-22946, a TLS upgrade bypass in curl that can force cleartext transmission, and urges users to patch immediately.

    0000065
    26 followersView on X
CPE platform detail47 entries

47 of 47 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSdebiandebian_linux9.0--
OSfedoraprojectfedora33--
OSfedoraprojectfedora35--
Apphaxxcurl---
Appnetappcloud_backup---
Appnetappclustered_data_ontap---
HWnetapph300e---
OSnetapph300e_firmware---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500e---
OSnetapph500e_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph700e---
OSnetapph700e_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
Appnetapponcommand_insight---
Appnetapponcommand_workflow_automation---
Appnetappsnapcenter---
HWnetappsolidfire_baseboard_management_controller---
OSnetappsolidfire_baseboard_management_controller_firmware---
Apporaclecommerce_guided_search11.3.2--
Apporaclecommunications_cloud_native_core_binding_support_function1.11.0--
Apporaclecommunications_cloud_native_core_binding_support_function22.1.3--
Apporaclecommunications_cloud_native_core_console22.2.0--
Apporaclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0--
Apporaclecommunications_cloud_native_core_network_repository_function1.15.0--
Apporaclecommunications_cloud_native_core_network_repository_function1.15.1--
Apporaclecommunications_cloud_native_core_network_repository_function22.1.0--
Apporaclecommunications_cloud_native_core_network_repository_function22.2.0--
Apporaclecommunications_cloud_native_core_network_slice_selection_function1.8.0--
Apporaclecommunications_cloud_native_core_security_edge_protection_proxy22.1.1--
Apporaclecommunications_cloud_native_core_service_communication_proxy1.15.0--
Apporaclemysql_server---
Apporaclepeoplesoft_enterprise_peopletools8.57--
Apporaclepeoplesoft_enterprise_peopletools8.58--
Apporaclepeoplesoft_enterprise_peopletools8.59--
Appsiemenssinec_infrastructure_network_services---
Appsplunkuniversal_forwarder---
Appsplunkuniversal_forwarder9.1.0--

Explore more