Vulnerability Name:

CVE-2021-25217 (CCN-202604)

Assigned:2021-05-26
Published:2021-05-26
Updated:2023-05-03
Summary:
CVSS v3 Severity:7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
8.8 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.7 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:3.3 Low (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
6.1 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-25217

Source: security-officer@isc.org
Type: Mailing List, Patch, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Patch, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Patch, Third Party Advisory
security-officer@isc.org

Source: XF
Type: UNKNOWN
isc-dhcp-cve202125217-dos(202604)

Source: CCN
Type: ISC Web site
CVE-2021-25217: A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient

Source: security-officer@isc.org
Type: Exploit, Vendor Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: UNKNOWN
security-officer@isc.org

Source: security-officer@isc.org
Type: Third Party Advisory
security-officer@isc.org

Source: CCN
Type: IBM Security Bulletin 6490433 (i)
ISC DHCP for IBM i is affected by CVE-2021-25217

Source: CCN
Type: IBM Security Bulletin 6498095 (System Storage TS4500 Tape Library)
TS4500 is affected by CVE-2021-25217

Source: CCN
Type: IBM Security Bulletin 6498497 (Cloud Foundry Migration Runtime)
Multiple security vulnerabilities affect IBM Cloud Foundry Migration Runtime

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:rhel_els:6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:isc:dhcp:4.1.1:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.1.1:b1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.1.1:b2:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.1.1:b3:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.1.1:rc1:*:*:*:*:*:*
  • AND
  • cpe:/o:ibm:i:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8032
    P
    libgit2-1_3-1.3.0-150400.3.6.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7959
    P
    libquicktime-1.2.4+git20180804.fff99cd-1.19 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7481
    P
    dhcp-4.3.6.P1-150000.6.17.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51568
    P
    Security update for pixman (Important)
    2022-11-23
    oval:org.opensuse.security:def:712
    P
    Security update for gnutls (Important)
    2022-08-26
    oval:org.opensuse.security:def:95264
    P
    Security update for logrotate (Important)
    2022-07-14
    oval:org.opensuse.security:def:3472
    P
    dhcp-4.3.3-10.16.4 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3613
    P
    libjavascriptcoregtk-4_0-18-2.24.4-2.47.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3427
    P
    apache-commons-beanutils-1.9.2-3.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94537
    P
    dhcp-4.3.6.P1-6.11.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94539
    P
    dnsmasq-2.86-150400.14.3 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95102
    P
    dhcp-relay-4.3.6.P1-6.11.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2907
    P
    dhcp-4.3.6.P1-6.11.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6034
    P
    Security update for the Linux Kernel (Important)
    2022-05-12
    oval:org.opensuse.security:def:101977
    P
    Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP3) (Important)
    2022-04-25
    oval:org.opensuse.security:def:99464
    P
    (Moderate)
    2022-03-30
    oval:org.opensuse.security:def:112151
    P
    dhcp-4.4.2.P1-2.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105687
    P
    dhcp-4.4.2.P1-2.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:97022
    P
    libvirt-5.1.0-6.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:101252
    P
    bsdtar-3.4.2-2.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:99663
    P
    (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:99971
    P
    (Important)
    2021-07-12
    oval:org.opensuse.security:def:111562
    P
    Security update for dhcp (Important)
    2021-07-11
    oval:com.redhat.rhsa:def:20212419
    P
    RHSA-2021:2419: dhcp security update (Important)
    2021-06-15
    oval:com.redhat.rhsa:def:20212357
    P
    RHSA-2021:2357: dhcp security update (Important)
    2021-06-09
    oval:com.redhat.rhsa:def:20212359
    P
    RHSA-2021:2359: dhcp security update (Important)
    2021-06-09
    oval:org.opensuse.security:def:111419
    P
    Security update for dhcp (Important)
    2021-06-03
    oval:org.opensuse.security:def:93564
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:93065
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:101443
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:9714
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:70405
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:67123
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:98878
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:94379
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:96040
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:73824
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:92514
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:99952
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:8962
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:69655
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:64516
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:117433
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:93741
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:93218
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:107918
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:10086
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:91928
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:102730
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:69048
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:99073
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:93250
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:75873
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:92713
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:100287
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:9332
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:69854
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:5716
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:64702
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:118492
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:93956
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:1609
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:108643
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:10265
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:92123
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:99105
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:8587
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:69121
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:99265
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:93407
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:76191
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:92912
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:100616
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:9515
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:70226
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:66805
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:94167
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:109396
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:73638
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:92315
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:99640
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:8767
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:69472
    P
    Security update for dhcp (Important)
    2021-06-02
    oval:org.opensuse.security:def:31181
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:56023
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:83407
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:41266
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:43244
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:126712
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:33658
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:58755
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:86092
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:29370
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:51897
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:38121
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:88439
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:31628
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:57004
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:84149
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:23580
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:44545
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:127109
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:33916
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:59481
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:86564
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:30080
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:55193
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:82577
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:38814
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:89136
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:32100
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:57451
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:84607
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:23909
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:45696
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:34447
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:59739
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:87396
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:30200
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:55903
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:83287
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:40115
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:89394
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:125542
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:32932
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:57923
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:85645
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:26063
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:60270
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:88126
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:5050
    P
    Security update for dhcp (Important)
    2021-06-01
    BACK
    isc dhcp 4.1.1
    isc dhcp 4.1.1 b1
    isc dhcp 4.1.1 b2
    isc dhcp 4.1.1 b3
    isc dhcp 4.1.1 rc1
    ibm i 7.1
    ibm i 7.2
    ibm i 7.3
    ibm i 7.4