peter bassill · operator
$ cve CVE-2021-42377 JSON

CVE-2021-42377

9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.62% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-590
On CISA KEVno
Public exploitnone known
Published2021-11-15
Last modified2026-06-17

Affected (19)

VendorProduct
busyboxbusybox
fedoraprojectfedora
netappcloud backup
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware
netapphci management node
netappsolidfire

References

→ the Explorer  ·  watch your stack  ·  NVD