7.7
CVE-2021-23017
- EPSS 76.12%
- Veröffentlicht 01.06.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:09
- Quelle f5sirt@f5.com
- Teams Watchlist Login
- Unerledigt Login
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version33
Fedoraproject ≫ Fedora Version34
Netapp ≫ Ontap Select Deploy Administration Utility Version-
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Communications Control Plane Monitor Version3.4
Oracle ≫ Communications Control Plane Monitor Version4.2
Oracle ≫ Communications Control Plane Monitor Version4.3
Oracle ≫ Communications Control Plane Monitor Version4.4
Oracle ≫ Communications Fraud Monitor Version >= 3.4 <= 4.4
Oracle ≫ Communications Operations Monitor Version3.4
Oracle ≫ Communications Operations Monitor Version4.2
Oracle ≫ Communications Operations Monitor Version4.3
Oracle ≫ Communications Operations Monitor Version4.4
Oracle ≫ Communications Session Border Controller Version8.4
Oracle ≫ Communications Session Border Controller Version9.0
Oracle ≫ Enterprise Communications Broker Version3.3.0
Oracle ≫ Enterprise Session Border Controller Version8.4
Oracle ≫ Enterprise Session Border Controller Version9.0
Oracle ≫ Enterprise Telephony Fraud Monitor Version3.4
Oracle ≫ Enterprise Telephony Fraud Monitor Version4.2
Oracle ≫ Enterprise Telephony Fraud Monitor Version4.3
Oracle ≫ Enterprise Telephony Fraud Monitor Version4.4
Oracle ≫ Goldengate Version < 21.4.0.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 76.12% | 0.989 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.7 | 2.2 | 5.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-193 Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.