7.5
CVE-2021-29662
- EPSS 0.36%
- Veröffentlicht 31.03.2021 18:15:16
- Zuletzt bearbeitet 21.11.2024 06:01:36
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Data::validate::ip Project ≫ Data::validate::ip SwPlatformperl Version <= 0.29
Netapp ≫ Snapcenter Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.36% | 0.57 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-704 Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.