CVE-2021-20322

Advisory lineage Upstream: 0 Downstream: 34
Modified
Published: 18 Feb 2022, 17:50
Last modified:03 Aug 2024, 17:37

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.4 HIGH
v3.1 (nvd)
EPSS Score
0.14% LOW
0% probability +0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Feb 2022, 17:50
Published
Vulnerability first disclosed
03 Aug 2024, 17:37
Last Modified
Vulnerability information updated

Description

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.14% Percentile: 33%

Techniques & Countermeasures

  • CWE-330Use of Insufficiently Random Values

    The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0

  • fedoraprojectfedora

    34

  • linuxlinux_kernel

    ≤ 5.14.21

  • netappactive_iq_unified_manager

    na

  • netappaff_a700s

    na

  • netappaff_baseboard_management_controller

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.1

  • netappfas_baseboard_management_controller

    na

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • netapphci_compute_node_firmware

    na

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire\,_enterprise_sds_\&_hci_storage_node

    na

  • oraclecommunications_cloud_native_core_binding_support_function

    22.1.3

  • oraclecommunications_cloud_native_core_network_exposure_function

    22.1.1

  • oraclecommunications_cloud_native_core_policy

    22.2.0

References (9)