ZeroHour

CVE-2021-3772

CVSS 3.1
6.5 medium
EPSS
1%p67
Published
()
Modified
Description

A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.

Vendors
linuxredhatdebianoraclenetapp
Products
linux kernel, enterprise linux, debian linux, communications cloud native core binding support function, communications cloud native core network exposure function, communications cloud native core policy, e-series santricity os controller, solidfire \& hci management node, solidfire \& hci storage node, hci compute node, h300s firmware, h500s firmware
Weakness
CWE-354
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.