Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-20322


A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.


Published

2022-02-18T18:15:09.013

Last Modified

2024-11-21T05:46:22.573

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-330
  • Type: Primary
    CWE-330

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel ≤ 5.14.21 Yes
Operating System fedoraproject fedora 34 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp e-series_santricity_os_controller ≤ 11.70.1 Yes
Application netapp solidfire\,_enterprise_sds_\&_hci_storage_node - Yes
Application netapp solidfire_\&_hci_management_node - Yes
Operating System netapp fas_baseboard_management_controller_firmware - Yes
Hardware netapp fas_baseboard_management_controller 8300 No
Operating System netapp fas_baseboard_management_controller_firmware - Yes
Hardware netapp fas_baseboard_management_controller 8700 No
Operating System netapp aff_baseboard_management_controller_firmware - Yes
Hardware netapp aff_baseboard_management_controller a400 No
Operating System netapp aff_a700s_firmware - Yes
Hardware netapp aff_a700s - No
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp h700e_firmware - Yes
Hardware netapp h700e - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No
Operating System netapp h500e_firmware - Yes
Hardware netapp h500e - No
Operating System netapp h300e_firmware - Yes
Hardware netapp h300e - No
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp hci_compute_node_firmware - Yes
Hardware netapp hci_compute_node - No
Application oracle communications_cloud_native_core_binding_support_function 22.1.3 Yes
Application oracle communications_cloud_native_core_network_exposure_function 22.1.1 Yes
Application oracle communications_cloud_native_core_policy 22.2.0 Yes

References