CVE-2021-26428
published 2021-08-12CVE-2021-26428: Azure Sphere Information Disclosure Vulnerability Azure Sphere Information Disclosure Vulnerability
medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.74%
50.4th percentile
Azure Sphere Information Disclosure Vulnerability
Azure Sphere Information Disclosure Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_sphere | >= 20.00 < 21.07 | 21.07 |
| msrc | azure_sphere | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
cvelistv54.4MEDIUM
vendor_msrc4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Sphere Information Disclosure Vulnerability
vendor_msrc·2021-08-10·CVSS 4.4
CVE-2021-26428 [MEDIUM] Azure Sphere Information Disclosure Vulnerability
Azure Sphere Information Disclosure Vulnerability
FAQ: What version of Azure Sphere has the update that protects from this vulnerability?
All versions of Azure Sphere that are 21.07 and higher are protected from this vulnerability.
How do I ensure my Azure Sphere device has the update?
If your device is new or has not been connected to the internet for a while, connect the device to a secure, private local network with internet access and allow the device to automatically update itself. If the device is already online, verify that the operating system version 21.07 has been installed using the Azure Sphere CLI command:
azsphere device show-os-version
If the device is connected to the internet and does not yet have the latest update, check the update status with the following Azure Sphere
CVEList
Azure Sphere Information Disclosure Vulnerability
cvelistv5·2021-08-12·CVSS 4.4
CVE-2021-26428 [MEDIUM] Azure Sphere Information Disclosure Vulnerability
Azure Sphere Information Disclosure Vulnerability
Azure Sphere Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-08-10·CVSS 9.9
CVE-2021-26424 [CRITICAL] Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Martin Lee.
Microsoft released its monthly security update Tuesday, disclosing 44 vulnerabilities in the company’s firmware and software. This is the fewest amount of vulnerabilities Microsoft has patched in a month in more than two years.
There are only nine critical vulnerabilities included in this release, and the remainder is “important.”
The most serious of the issues is CVE-2021-26424 a remote code executing vulnerability which exists in the Windows TCP/IP protocol implementation. An attacker could remotely trigger this vulnerability from a Hyper-V guest by sending a specially crafted TCP/IP packet to a host utilizing the TCP/IP protocol stack. This raises the possibility of a malicious program running in a virtual machine compromising the h
Talos
Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-08-10·CVSS 9.9
[CRITICAL] Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Martin Lee.
Microsoft released its monthly security update Tuesday, disclosing 44 vulnerabilities in the company’s firmware and software. This is the fewest amount of vulnerabilities Microsoft has patched in a month in more than two years.
There are only nine critical vulnerabilities included in this release, and the remainder is “important.”
The most serious of the issues is CVE-2021-26424 a remote code executing vulnerability which exists in the Windows TCP/IP protocol implementation. An attacker could remotely trigger this vulnerability from a Hyper-V guest by sending a specially crafted TCP/IP packet to a host utilizing the TCP/IP protocol stack. This raise
2021-08-12
Published