CVE-2021-47347
published 2024-05-21CVE-2021-47347: In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls…
PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.27%
66.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
wl1251: Fix possible buffer overflow in wl1251_cmd_scan
Function wl1251_cmd_scan calls memcpy without checking the length.
Harden by checking the length is within the maximum allowed size.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 57ad99ae3c6738ba87bad259bb57c641ca68ebf6 | 57ad99ae3c6738ba87bad259bb57c641ca68ebf6 |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < d3d8b9c9c7843dce31e284927d4c9904fd5a510a | d3d8b9c9c7843dce31e284927d4c9904fd5a510a |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 0f6c0488368c9ac1aa685821916fadba32f5d1ef | 0f6c0488368c9ac1aa685821916fadba32f5d1ef |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 115103f6e3f1c26c473766c16439c7c8b235529a | 115103f6e3f1c26c473766c16439c7c8b235529a |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < d71dddeb5380613f9ef199f3e7368fd78fb1a46e | d71dddeb5380613f9ef199f3e7368fd78fb1a46e |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < c5e4a10d7bd5d4f419d8b9705dff60cf69b302a1 | c5e4a10d7bd5d4f419d8b9705dff60cf69b302a1 |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 302e2ee34c5f7c5d805b7f835d9a6f2b43474e2a | 302e2ee34c5f7c5d805b7f835d9a6f2b43474e2a |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < 40af3960a15339e8bbd3be50c3bc7b35e1a0b6ea | 40af3960a15339e8bbd3be50c3bc7b35e1a0b6ea |
| linux | linux | >= 2f01a1f58889fbfeb68b1bc1b52e4197f3333490 < d10a87a3535cce2b890897914f5d0d83df669c63 | d10a87a3535cce2b890897914f5d0d83df669c63 |
| linux | linux_kernel | < 4.4.276 | 4.4.276 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 4.10 < 4.14.240 | 4.14.240 |
| linux | linux_kernel | >= 4.15 < 4.19.198 | 4.19.198 |
| linux | linux_kernel | >= 4.20 < 5.4.133 | 5.4.133 |
| linux | linux_kernel | >= 4.5 < 4.9.276 | 4.9.276 |
| linux | linux_kernel | >= 5.11 < 5.12.18 | 5.12.18 |
| linux | linux_kernel | >= 5.13 < 5.13.3 | 5.13.3 |
| linux | linux_kernel | >= 5.5 < 5.10.51 | 5.10.51 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wl1251: Fix possible buffer overflow in wl1251_cmd_scan
vendor_redhat·2024-05-21·CVSS 8.8
CVE-2021-47347 [HIGH] CWE-122 kernel: wl1251: Fix possible buffer overflow in wl1251_cmd_scan
kernel: wl1251: Fix possible buffer overflow in wl1251_cmd_scan
In the Linux kernel, the following vulnerability has been resolved:
wl1251: Fix possible buffer overflow in wl1251_cmd_scan
Function wl1251_cmd_scan calls memcpy without checking the length.
Harden by checking the length is within the maximum allowed size.
A vulnerability was discovered in the Linux kernel's wl1251 wireless driver, where the wl1251_cmd_scan function used memcpy without checking if the data length was within safe limits. This could potentially lead to a buffer overflow, which might cause system instability or crashes.
Statement: This vulnerability is rated as a moderate severity because this issue can lead to a system crash or instability, it does not pose an immediate security risk or data compromise.
Miti
Debian
CVE-2021-47347: linux - In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix...
vendor_debian·2021·CVSS 8.8
CVE-2021-47347 [HIGH] CVE-2021-47347: linux - In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix...
In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls memcpy without checking the length. Harden by checking the length is within the maximum allowed size.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
GHSA
GHSA-3gcc-j58h-xmv8: In the Linux kernel, the following vulnerability has been resolved:
wl1251: Fix possible buffer overflow in wl1251_cmd_scan
Function wl1251_cmd_scan
ghsa_unreviewed·2024-05-21
CVE-2021-47347 [HIGH] CWE-120 GHSA-3gcc-j58h-xmv8: In the Linux kernel, the following vulnerability has been resolved:
wl1251: Fix possible buffer overflow in wl1251_cmd_scan
Function wl1251_cmd_scan
In the Linux kernel, the following vulnerability has been resolved:
wl1251: Fix possible buffer overflow in wl1251_cmd_scan
Function wl1251_cmd_scan calls memcpy without checking the length.
Harden by checking the length is within the maximum allowed size.
OSV
CVE-2021-47347: In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan c
osv·2024-05-21·CVSS 8.8
CVE-2021-47347 [HIGH] CVE-2021-47347: In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan c
In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls memcpy without checking the length. Harden by checking the length is within the maximum allowed size.
Suricata
ET EXPLOIT Possible Cisco Data Center Network Manager - Unauthenticated File Upload (CVE-2019-1620)
suricata·2021-07-27·CVSS 9.8
CVE-2019-1620 [CRITICAL] ET EXPLOIT Possible Cisco Data Center Network Manager - Unauthenticated File Upload (CVE-2019-1620)
ET EXPLOIT Possible Cisco Data Center Network Manager - Unauthenticated File Upload (CVE-2019-1620)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Cisco Data Center Network Manager - Unauthenticated File Upload (CVE-2019-1620)"; flow:established,to_server; http.uri; content:"/fm/fileUpload"; endswith; fast_pattern; http.request_body; content:"application|2f|octet-stream"; content:"name=|22|fname|22|"; content:"name=|22|uploadDir|22|"; http.header_names; to_lowercase; content:!"cookie|0d 0a|"; reference:url,www.exploit-db.com/exploits/47347; reference:cve,2019-1620; classtype:attempted-admin; sid:2033446; rev:3; metadata:created_at 2021_07_27, cve CVE_2019_1620, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus,
Suricata
ET EXPLOIT Possible Cisco Data Center Network Manager - Log Retrieval (CVE-2019-1622)
suricata·2021-07-27·CVSS 5.3
CVE-2019-1622 [MEDIUM] ET EXPLOIT Possible Cisco Data Center Network Manager - Log Retrieval (CVE-2019-1622)
ET EXPLOIT Possible Cisco Data Center Network Manager - Log Retrieval (CVE-2019-1622)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Cisco Data Center Network Manager - Log Retrieval (CVE-2019-1622)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/fm/log/fmlogs.zip"; endswith; fast_pattern; reference:url,www.exploit-db.com/exploits/47347; reference:cve,2019-1622; classtype:attempted-recon; sid:2033444; rev:1; metadata:attack_target Server, created_at 2021_07_27, cve CVE_2019_1622, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2021_07_27, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Fac
Suricata
ET EXPLOIT Possible Cisco Data Center Network Manager - Authenticated File Upload (CVE-2019-1620)
suricata·2021-07-27·CVSS 9.8
CVE-2019-1620 [CRITICAL] ET EXPLOIT Possible Cisco Data Center Network Manager - Authenticated File Upload (CVE-2019-1620)
ET EXPLOIT Possible Cisco Data Center Network Manager - Authenticated File Upload (CVE-2019-1620)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Cisco Data Center Network Manager - Authenticated File Upload (CVE-2019-1620)"; flow:established,to_server; http.uri; content:"/fm/fileUpload"; endswith; fast_pattern; http.request_body; content:"application|2f|octet-stream"; content:"name=|22|fname|22|"; content:"name=|22|uploadDir|22|"; http.header_names; to_lowercase; content:"cookie|0d 0a|"; reference:url,www.exploit-db.com/exploits/47347; reference:cve,2019-1620; classtype:attempted-admin; sid:2033445; rev:3; metadata:created_at 2021_07_27, cve CVE_2019_1620, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updat
No public exploits indexed.
https://git.kernel.org/stable/c/0f6c0488368c9ac1aa685821916fadba32f5d1efhttps://git.kernel.org/stable/c/115103f6e3f1c26c473766c16439c7c8b235529ahttps://git.kernel.org/stable/c/302e2ee34c5f7c5d805b7f835d9a6f2b43474e2ahttps://git.kernel.org/stable/c/40af3960a15339e8bbd3be50c3bc7b35e1a0b6eahttps://git.kernel.org/stable/c/57ad99ae3c6738ba87bad259bb57c641ca68ebf6https://git.kernel.org/stable/c/c5e4a10d7bd5d4f419d8b9705dff60cf69b302a1https://git.kernel.org/stable/c/d10a87a3535cce2b890897914f5d0d83df669c63https://git.kernel.org/stable/c/d3d8b9c9c7843dce31e284927d4c9904fd5a510ahttps://git.kernel.org/stable/c/d71dddeb5380613f9ef199f3e7368fd78fb1a46ehttps://git.kernel.org/stable/c/0f6c0488368c9ac1aa685821916fadba32f5d1efhttps://git.kernel.org/stable/c/115103f6e3f1c26c473766c16439c7c8b235529ahttps://git.kernel.org/stable/c/302e2ee34c5f7c5d805b7f835d9a6f2b43474e2ahttps://git.kernel.org/stable/c/40af3960a15339e8bbd3be50c3bc7b35e1a0b6eahttps://git.kernel.org/stable/c/57ad99ae3c6738ba87bad259bb57c641ca68ebf6https://git.kernel.org/stable/c/c5e4a10d7bd5d4f419d8b9705dff60cf69b302a1https://git.kernel.org/stable/c/d10a87a3535cce2b890897914f5d0d83df669c63https://git.kernel.org/stable/c/d3d8b9c9c7843dce31e284927d4c9904fd5a510ahttps://git.kernel.org/stable/c/d71dddeb5380613f9ef199f3e7368fd78fb1a46e
2024-05-21
Published