6.5
CVE-2021-3772
- EPSS 0.16%
- Veröffentlicht 02.03.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:23
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.15.0
Redhat ≫ Enterprise Linux Version8.0
Debian ≫ Debian Linux Version9.0
Debian ≫ Debian Linux Version10.0
Oracle ≫ Communications Cloud Native Core Binding Support Function Version22.1.3
Oracle ≫ Communications Cloud Native Core Network Exposure Function Version22.1.1
Oracle ≫ Communications Cloud Native Core Policy Version22.2.0
Netapp ≫ E-series Santricity Os Controller Version11.0
Netapp ≫ E-series Santricity Os Controller Version11.0.0
Netapp ≫ E-series Santricity Os Controller Version11.20
Netapp ≫ E-series Santricity Os Controller Version11.25
Netapp ≫ E-series Santricity Os Controller Version11.30
Netapp ≫ E-series Santricity Os Controller Version11.30.5r3
Netapp ≫ E-series Santricity Os Controller Version11.40
Netapp ≫ E-series Santricity Os Controller Version11.40.3r2
Netapp ≫ E-series Santricity Os Controller Version11.40.5
Netapp ≫ E-series Santricity Os Controller Version11.50.1
Netapp ≫ E-series Santricity Os Controller Version11.50.2 Update-
Netapp ≫ E-series Santricity Os Controller Version11.50.2 Updatep1
Netapp ≫ E-series Santricity Os Controller Version11.60
Netapp ≫ E-series Santricity Os Controller Version11.60.0
Netapp ≫ E-series Santricity Os Controller Version11.60.1
Netapp ≫ E-series Santricity Os Controller Version11.60.3
Netapp ≫ E-series Santricity Os Controller Version11.70.1
Netapp ≫ E-series Santricity Os Controller Version11.70.2
Netapp ≫ Solidfire & Hci Management Node Version-
Netapp ≫ Solidfire & Hci Storage Node Version-
Netapp ≫ Hci Compute Node Version-
Netapp ≫ H300s Firmware Version-
Netapp ≫ H500s Firmware Version-
Netapp ≫ H700s Firmware Version-
Netapp ≫ H410s Firmware Version-
Netapp ≫ H410c Firmware Version-
Netapp ≫ H610c Firmware Version-
Netapp ≫ H610s Firmware Version-
Netapp ≫ H615c Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.376 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
|
nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
CWE-354 Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.