CVE-2021-26430
published 2021-08-12CVE-2021-26430: Azure Sphere Denial of Service Vulnerability Azure Sphere Denial of Service Vulnerability
medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.63%
46.1th percentile
Azure Sphere Denial of Service Vulnerability
Azure Sphere Denial of Service Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_sphere | >= 20.00 < 21.07 | 21.07 |
| msrc | azure_sphere | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
cvelistv56.0MEDIUM
vendor_msrc6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Sphere Denial of Service Vulnerability
vendor_msrc·2021-08-10·CVSS 6.0
CVE-2021-26430 [MEDIUM] Azure Sphere Denial of Service Vulnerability
Azure Sphere Denial of Service Vulnerability
FAQ: What version of Azure Sphere has the update that protects from this vulnerability?
All versions of Azure Sphere that are 21.07 and higher are protected from this vulnerability.
How do I ensure my Azure Sphere device has the update?
If your device is new or has not been connected to the internet for a while, connect the device to a secure, private local network with internet access and allow the device to automatically update itself. If the device is already online, verify that the operating system version 21.07 has been installed using the Azure Sphere CLI command:
azsphere device show-os-version
If the device is connected to the internet and does not yet have the latest update, check the update status with the following Azure Sphere CLI c
CVEList
Azure Sphere Denial of Service Vulnerability
cvelistv5·2021-08-12·CVSS 6.0
CVE-2021-26430 [MEDIUM] Azure Sphere Denial of Service Vulnerability
Azure Sphere Denial of Service Vulnerability
Azure Sphere Denial of Service Vulnerability
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-08-10·CVSS 9.9
CVE-2021-26424 [CRITICAL] Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Martin Lee.
Microsoft released its monthly security update Tuesday, disclosing 44 vulnerabilities in the company’s firmware and software. This is the fewest amount of vulnerabilities Microsoft has patched in a month in more than two years.
There are only nine critical vulnerabilities included in this release, and the remainder is “important.”
The most serious of the issues is CVE-2021-26424 a remote code executing vulnerability which exists in the Windows TCP/IP protocol implementation. An attacker could remotely trigger this vulnerability from a Hyper-V guest by sending a specially crafted TCP/IP packet to a host utilizing the TCP/IP protocol stack. This raises the possibility of a malicious program running in a virtual machine compromising the h
Talos
Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-08-10·CVSS 9.9
[CRITICAL] Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Martin Lee.
Microsoft released its monthly security update Tuesday, disclosing 44 vulnerabilities in the company’s firmware and software. This is the fewest amount of vulnerabilities Microsoft has patched in a month in more than two years.
There are only nine critical vulnerabilities included in this release, and the remainder is “important.”
The most serious of the issues is CVE-2021-26424 a remote code executing vulnerability which exists in the Windows TCP/IP protocol implementation. An attacker could remotely trigger this vulnerability from a Hyper-V guest by sending a specially crafted TCP/IP packet to a host utilizing the TCP/IP protocol stack. This raise
2021-08-12
Published