peter bassill · operator
$ cve CVE-2021-23017 JSON

CVE-2021-23017 EXPLOIT

7.7
HIGH · CVSS 3.1 · EPSS 53.5% (pctl 99)

Patch early

A public exploit exists.

Description

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Scoring

CVSS7.7 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
EPSS53.46% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-193
On CISA KEVno
Public exploityes
Published2021-06-01
Last modified2026-06-17

Affected (13)

VendorProduct
f5nginx
fedoraprojectfedora
netappontap select deploy administration utility
openrestyopenresty
oracleblockchain platform
oraclecommunications control plane monitor
oraclecommunications fraud monitor
oraclecommunications operations monitor
oraclecommunications session border controller
oracleenterprise communications broker
oracleenterprise session border controller
oracleenterprise telephony fraud monitor
oraclegoldengate

Public exploits

SourceTitleDate
exploit-dbNginx 1.20.0 - Denial of Service (DOS)2022-07-11

References

→ the Explorer  ·  watch your stack  ·  NVD