CVE-2021-21783
published 2021-03-25CVE-2021-21783: A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.98%
91.3th percentile
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gsoap | — | — |
| genivia | gsoap | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.5.0 | — |
| oracle | communications_eagle_application_processor | 16.1.0 – 16.4.0 | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_lsms | — | — |
| oracle | communications_lsms | — | — |
| oracle | communications_lsms | — | — |
| oracle | communications_lsms | — | — |
| oracle | tekelec_virtual_operating_environment | 3.4.0 – 3.7.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via a specially crafted SOAP request to the WS-Addressing plugin in gSOAP; monitor for malformed/unexpected WS-Addressing headers in inbound SOAP/HTTP traffic. ↗
- →The vulnerable component is the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107; flag or audit deployments running this specific version. ↗
- →Attack is delivered over HTTP and is remotely exploitable with no authentication required (CVSS 9.8); prioritize perimeter detection on HTTP-exposed gSOAP services. ↗
- ·The vulnerability specifically requires the WS-Addressing plugin to be enabled in gSOAP; deployments not using this plugin are not affected. ↗
- ·Debian tracking shows the issue remains open across multiple releases (bookworm, bullseye, forky, sid, trixie) as of the last update; patch availability should be verified per distribution. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Platform (gSOAP) — CVE-2021-21783
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2021-21783 [CRITICAL] Oracle Oracle Communications Risk Matrix: Platform (gSOAP) — CVE-2021-21783
Oracle Oracle Communications Risk Matrix: Platform (gSOAP) vulnerability
CVE: CVE-2021-21783
CVSS: 9.8
Protocol: GSOAP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (gSOAP) — CVE-2021-21783
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2021-21783 [CRITICAL] Oracle Oracle Communications Risk Matrix: Platform (gSOAP) — CVE-2021-21783
Oracle Oracle Communications Risk Matrix: Platform (gSOAP) vulnerability
CVE: CVE-2021-21783
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (gSOAP) — CVE-2021-21783
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2021-21783 [CRITICAL] Oracle Oracle Communications Risk Matrix: Platform (gSOAP) — CVE-2021-21783
Oracle Oracle Communications Risk Matrix: Platform (gSOAP) vulnerability
CVE: CVE-2021-21783
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Debian
CVE-2021-21783: gsoap - A code execution vulnerability exists in the WS-Addressing plugin functionality ...
vendor_debian·2021·CVSS 9.8
CVE-2021-21783 [CRITICAL] CVE-2021-21783: gsoap - A code execution vulnerability exists in the WS-Addressing plugin functionality ...
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-pf2j-vqc7-8qr7: A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2
ghsa_unreviewed·2022-05-24
CVE-2021-21783 [CRITICAL] CWE-190 GHSA-pf2j-vqc7-8qr7: A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
OSV
CVE-2021-21783: A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2
osv·2021-03-25·CVSS 9.8
CVE-2021-21783 [CRITICAL] CVE-2021-21783: A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1245https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://talosintelligence.com/vulnerability_reports/TALOS-2021-1245https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-25
Published