cbcvebase.
CVE-2021-29507
published 2021-05-28

CVE-2021-29507: GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing…

PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.75%
51.2th percentile
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a workaround, one may check the integrity of information in configuration file manually.

Affected

6 ranges
VendorProductVersion rangeFixed in
covesadlt-daemon>= 0 < 2.18.8-12.18.8-1
covesadlt-daemon>= 0 < 2.18.8-12.18.8-1
covesadlt-daemon>= 0 < 2.18.8-12.18.8-1
debiandlt-daemon< dlt-daemon 2.18.8-1 (bookworm)dlt-daemon 2.18.8-1 (bookworm)
genividiagnostic_log_and_trace2.10.0 – 2.18.6
genividlt-daemon

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian5.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.