CVE-2021-3773Sensitive Information Exposure in Oracle Communications Cloud Native Core Network Exposure Function

Severity
9.8CRITICALNVD
EPSS
0.7%
top 29.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateFeb 14

Description

A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel5.155.15.15+1
Palo Altopaloalto/pan-os
CVEListV5linux/linux_kernelkernel 5.14.0-49.el9, kernel 5.15.15-100.fc34, kernel 5.15.15-200.fc35

Also affects: Fedora 34, Enterprise Linux 6.0, 7.0, 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3xjv-m925-6jcj: A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network a2022-02-17
CVEList
CVE-2021-3773: A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network a2022-02-16
OSV
CVE-2021-3773: A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network a2022-02-16

📋Vendor Advisories

5
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Microsoft
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.2022-02-08
Red Hat
kernel: lack of port sanity checking in natd and netfilter leads to exploit of OpenVPN clients2021-09-08
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Order Management (Spring Web Services) — CVE-2019-37732021-04-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Spring Web Services) — CVE-2019-37732021-01-15
CVE-2021-3773 — Sensitive Information Exposure | cvebase